First published: Thu Mar 05 2009(Updated: )
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Members Cv Module | =1.0 | |
Php-fusion Php-fusion |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.