Description
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.
Remediation
References
Related Vulnerabilities
Drupal Core 9.2.x Multiple Security Bypass Vulnerabilities (9.2.0 - 9.2.5)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-3171)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-10188)
WordPress Plugin HB AUDIO GALLERY LITE Arbitrary File Download (1.0.0)