PHP-Fusion.Downloads.php.Command.Injection
Description
This indicates an attack attempt to exploit a Command Injection Vulnerability in PHP-Fusion.
The vulnerability is due to insufficient validation of HTTP request parameters in downloads.php. A remote unauthenticated attacker could exploit this vulnerability by sending an crafted HTTP request to the vulnerable server. Successful exploitation of this vulnerability could allow the attacker to execute command in the security context of the running server.
Affected Products
PHP-Fusion 9.03.50 and prior
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/php-fusion/PHP-Fusion/issues/2312
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |