Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx58-3c3p-x3pm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query.

PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query.

EPSS

Процентиль: 38%
0.00164
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query.

CVSS3: 8.8
fstec
почти 6 лет назад

Уязвимость компонентов «/submit.php» и «/infusions/downloads/downloads.php» CMS-системы PHP-Fusion, позволяющая нарушителю произвольные SQL-запросы

EPSS

Процентиль: 38%
0.00164
Низкий