CVE-2005-3159
Description
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in PHP-Fusion v6.00.109 messages.php via msg_view parameter allows remote unauthenticated attackers to execute arbitrary SQL commands.
Vulnerability
The vulnerability resides in messages.php of PHP-Fusion version 6.00.109. The msg_view parameter is insufficiently sanitized, enabling SQL injection. This issue is distinct from other SQL injection points reported for the same file (such as msg_send, pm_email_notify, and pm_save_sent) [1].
Exploitation
An attacker needs only network access to the vulnerable PHP-Fusion installation; no authentication is required. By crafting a malicious HTTP request to messages.php with a specially formed msg_view parameter (e.g., msg_view=' UNION SELECT ...), the attacker can inject arbitrary SQL commands [1]. No user interaction is necessary.
Impact
Successful exploitation allows the attacker to execute arbitrary SQL statements against the backend database. This can lead to disclosure of sensitive information such as user credentials and administrator passwords, and potentially complete compromise of the application and its data [1].
Mitigation
The vendor was reportedly aware of this issue and had likely fixed it before the disclosure in September 2005 [1]. Users should upgrade to the latest available version of PHP-Fusion. No explicit fixed version is documented in the provided reference. If upgrading is not immediately possible, input sanitization for the msg_view parameter should be enforced or access to messages.php restricted. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/14489nvdExploit
- www.s4a.cc/forum/archive/index.php/t-3585.htmlnvdVendor AdvisoryURL Repurposed
- marc.infonvd
- www.osvdb.org/18708nvd
News mentions
0No linked articles in our index yet.