Description
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.
Remediation
References
Related Vulnerabilities
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10353)
Squid Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-8449)
Jboss EAP Insertion of Sensitive Information into Log File Vulnerability (CVE-2019-10212)
phpMyAdmin Other Vulnerability (CVE-2007-0095)
Oracle Database Server CVE-2014-6578 Vulnerability (CVE-2014-6578)