PHP-Fusion.Downloads.php.Command.Injection

description-logoDescription

This indicates an attack attempt to exploit a Command Injection Vulnerability in PHP-Fusion.
The vulnerability is due to insufficient validation of HTTP request parameters in downloads.php. A remote unauthenticated attacker could exploit this vulnerability by sending an crafted HTTP request to the vulnerable server. Successful exploitation of this vulnerability could allow the attacker to execute command in the security context of the running server.

affected-products-logoAffected Products

PHP-Fusion 9.03.50 and prior

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/php-fusion/PHP-Fusion/issues/2312

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2020-12-09 16.976
Modified
Default_action:pass:drop
2020-12-01 16.971
New