7.5
CVSSv2

CVE-2014-8596

Published: 17/11/2014 Updated: 03/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.

Vulnerable Product Search on Vulmon Subscribe to Product

php-fusion php-fusion 7.02.07

Exploits

# Exploit Title: PHP-Fusion 70207 SQL Injection # Date: 06/11/2014 # Exploit Author: Mauricio Correa # Vendor Homepage: wwwphp-fusioncouk # Software Link: ufprdlsourceforgenet/project/php-fusion/PHP-Fusion%20Archives/7x/ PHP-Fusion-70207zip # Version: 70207 # Tested on: Linux OS (Debian) # CVE : CVE-2014-8596 GET /PHP-Fusio ...
PHP-Fusion version 70207 suffers from a remote SQL injection vulnerability ...