CVE-2006-2459
Php Fusion - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter.
Exploits (1)
References (9)
Scores
EPSS
0.0094
EPSS Percentile
76.3%
Details
Status
published
Products (2)
php_fusion/php_fusion
6.00.306
php_fusion/php_fusion
6.00.307
Published
May 19, 2006
Tracked Since
Feb 18, 2026