Unrated severityNVD Advisory· Published May 5, 2014· Updated May 6, 2026
CVE-2013-7375
CVE-2013-7375
Description
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.
Affected products
5cpe:2.3:a:php-fusion:php-fusion:7.02.01:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:php-fusion:php-fusion:7.02.01:*:*:*:*:*:*:*
- cpe:2.3:a:php-fusion:php-fusion:7.02.02:*:*:*:*:*:*:*
- cpe:2.3:a:php-fusion:php-fusion:7.02.03:*:*:*:*:*:*:*
- cpe:2.3:a:php-fusion:php-fusion:7.02.04:*:*:*:*:*:*:*
- cpe:2.3:a:php-fusion:php-fusion:7.02.05:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- osvdb.org/show/osvdb/90359nvd
- packetstormsecurity.com/files/120368/PHP-Fusion-CMS-7.02.05-SQL-Injection.htmlnvd
- packetstormsecurity.com/files/120598/PHP-Fusion-7.02.05-XSS-LFI-SQL-Injection.htmlnvd
- seclists.org/bugtraq/2013/Feb/80nvd
- seclists.org/fulldisclosure/2013/Feb/154nvd
- www.securityfocus.com/bid/58011nvd
- www.waraxe.us/advisory-97.htmlnvd
- vndh.net/note:php-fusion-70205-sql-injectionnvd
News mentions
0No linked articles in our index yet.