Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-1918

EPSS 2.19% · P85

Public Exploits 2

Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-1918

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHP-Fusion submit.php文件SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP-Fusion是一款基于PHP的内容管理系统。 PHP-Fusion的submit.php文件没有正确地过滤对submit_info[]参数的输入便在SQL查询中使用,远程攻击者可能利用此漏洞执行SQL注入攻击。 相关代码: 1. if ($stype == "l") { 2. 3. if (isset($_POST['submit_link'])) { 4. 5. if ($_POST['link_name'] != "" && $_POST['link_url'] != "" && $_POST
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-1918

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-1918

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-04-22 · 10 CVEs total

CVE-2008-1919YourFreeWorld Apartment 'listtest.php' SQL注入漏洞
CVE-2008-1920ICQ个人状态管理器远程溢出漏洞
CVE-2008-19215th Avenue Shopping Cart category_ID参数 SQL 注入漏洞
CVE-2008-1912DivX Player .SRT文件字幕解析缓冲区溢出漏洞
CVE-2008-1913Lasernet CMS index.php SQL注入漏洞
CVE-2008-1914BigAnt IM服务器HTTP GET请求远程栈溢出漏洞
CVE-2008-1915DevWorx BlogWorx 'view.asp' SQL注入漏洞
CVE-2008-1916drupal ubercart 多个跨站脚本攻击漏洞
CVE-2008-1917Amfphp 多个跨站脚本攻击漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-1918

No comments yet


Leave a comment