Vulnerabilities > CVE-2005-4517 - SQL-Injection vulnerability in PHP Fusion

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
php-fusion
exploit available

Summary

SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratings parameter in multiple scripts, such as ratings_include.php.

Exploit-Db

descriptionPHP-Fusion 6.00.3 (rating) Parameter Remote SQL Injection Exploit. CVE-2005-4517. Webapps exploit for php platform
idEDB-ID:1385
last seen2016-01-31
modified2005-12-23
published2005-12-23
reporterkrasza
sourcehttps://www.exploit-db.com/download/1385/
titlePHP-Fusion 6.00.3 rating Parameter Remote SQL Injection Exploit