PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-5335 - Vulnerability Database

PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-5335

Medium
Reference: CVE-2008-5335
Title: PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1 when magic_quotes_gpc is disabled allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters a different vector than CVE-2005-3157 CVE-2005-3158 CVE-2005-3159 CVE-2005-4005 and CVE-2006-2459.