Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
PHP-Fusion v6.00.109 SQL Injection and Info. Disclosure Dec 03 2005 12:50AM
xer0x west gmail com
In the latest version of PHP-Fusion, the content management system by Digitanium (php-fusion.co.uk), there is an SQL Error in messages.php that reveals path names and a table name, and someone could possibly manipulate the SQL database.
The error is as follows, it is with the Search and Sort option:...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus