PT-2007-4552 · Coldfusion · Fusetalk

Published

2007-06-19

·

Updated

2012-10-24

·

CVE-2007-3273

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FuseTalk version 2.0
Description A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. The exact vectors used for the attack are not specified.
Recommendations For FuseTalk version 2.0, consider restricting access to the index.cfm file as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3273

Affected Products

Fusetalk