Rewterz
Rewterz Threat Advisory – Adobe Multiple Security Vulnerabilities
June 17, 2020
Rewterz
Rewterz Threat Alert – Global Malicious Spam Campaign Using Black Lives Matter as a Lure
June 17, 2020

Rewterz Threat Advisory – PHP-Fusion SQL Injection Vulnerability

Severity

Medium

Analysis Summary

PHP-Fusion is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the PHPFusion/Feedback/Comments.ajax.php script using specific parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.

Impact

Data Manipulation

Affected Vendors

PHP-Fusion

Affected Products

PHP-Fusion 9.03.60

Remediation

Refer to vendor’s advisory for the list of affected products and upgraded patches.

https://www.php-fusion.co.uk/home.php