Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-736g-vp2f-c4v8

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

EPSS

Процентиль: 69%
0.006
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

EPSS

Процентиль: 69%
0.006
Низкий