Unrated severityNVD Advisory· Published Nov 17, 2014· Updated May 6, 2026
CVE-2014-8596
CVE-2014-8596
Description
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.
Affected products
1- cpe:2.3:a:php-fusion:php-fusion:7.02.07:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- packetstormsecurity.com/files/129053/PHP-Fusion-7.02.07-SQL-Injection.htmlnvdExploit
- www.exploit-db.com/exploits/35206nvdExploit
- www.xlabs.com.br/blog/nvdExploit
- osvdb.org/show/osvdb/112419nvd
- packetstormsecurity.com/files/133869/PHP-Fusion-7.02.07-Blind-SQL-Injection.htmlnvd
- seclists.org/fulldisclosure/2015/Oct/23nvd
- www.securityfocus.com/bid/71053nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/98583nvd
News mentions
0No linked articles in our index yet.