First published: Thu Mar 05 2009(Updated: )
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Members Cv Module | =1.0 | |
Jenkins |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0831 is classified as a medium severity vulnerability that allows SQL injection attacks.
To fix CVE-2009-0831, enable magic_quotes_gpc or apply an update that addresses the SQL injection in the Members CV module.
Remote authenticated users of PHP-Fusion Members CV module version 1.0 are impacted by CVE-2009-0831.
CVE-2009-0831 can be exploited by sending specially crafted SQL commands through the sortby parameter in members.php.
Yes, CVE-2009-0831 specifically affects installations of the Members CV module version 1.0 when magic_quotes_gpc is disabled.