Description
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.
Remediation
References
Related Vulnerabilities
WordPress Plugin UserPro-Community and User Profile Multiple Vulnerabilities (5.1.4)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-13082)
WordPress Plugin WP Prayer Multiple Cross-Site Request Forgery Vulnerabilities (1.6.5)
WordPress Plugin Dropbox Folder Share Server-Side Request Forgery (1.9.7)
ZenCart Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2024-5762)