CVE-2004-2437 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php or (3) the comment_id parameter to comments.php.
Reference
http://secunia.com/advisories/12686/ http://www.osvdb.org/10437 http://www.osvdb.org/10438 http://www.securityfocus.com/bid/11296 https://exchange.xforce.ibmcloud.com/vulnerabilities/17546
Share on: