Vulnerabilities > PHP Fusion > PHP Fusion > 6.0.306
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-09-11 | CVE-2006-4673 | SQL Injection vulnerability in PHP-Fusion News.PHP Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php. | 2.6 |