← Back

CVE-2006-4673

nvd nist
Published: Sep 11, 2006Modified: Apr 16, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

Affected (12)

1 product
Php Fusion
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Php Fusion
Up to 6.01.4
Version 6.0.105
Version 6.0.106
Version 6.0.107
Version 6.0.109
Version 6.0.110
Version 6.0.204
Version 6.0.206
Version 6.0.303
Version 6.0.304
Version 6.0.306
Version 6.0.307

References (14)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.