PHP-Fusion Database Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 2352

Synopsis

The remote host is running a version of PHP-Fusion that is prone to a SQL injection issue.

Description

The remote host is running a version of PHP-Fusion that is prone to a SQL injection issue. In versions prior to and including 4.01, an attacker may be able to manipulate and obtain potentially confidential data. In addition, there is also a flaw in the way that this version of PHP-Fusion handles upload code. An attacker exploiting this flaw would be able to upload malicious code that would then be run by unsuspecting web users. Finally, there is a flaw in the way that PHP-Fusion handles user-supplied input via the forum_search.php script. An attacker can potentially read confidential data from protected areas of the server.

Solution

Upgrade or patch according to vendor recommendations.

Plugin Details

Severity: High

ID: 2352

File Name: 2352.prm

Family: CGI

Published: 2004/10/06

Modified: 2016/01/15

Dependencies: 1442

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:H/RL:U/RC:ND

CVSSv3

Base Score: 7.3

Temporal Score: 7.3

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:H/RL:U/RC:X

Reference Information

CVE: CVE-2004-2438, CVE-2004-2437

BID: 11296, 12425

OSVDB: 10437, 10439