CVE
- Id
- 3654
- CVE No.
- CVE-2001-0848
- Status
- Candidate
- Description
- join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable.
- Phase
- Modified (20050703)
- Votes
- ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Bishop, Foat, Wall
- Comments
- Frech> XF:fusetalk-joincfm-sql-execution(7445)