FYI…

- http://secunia.com/advisories/17871/
"Release Date: 2005-12-05
Critical: Moderately critical
Impact: Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software: PHP-Fusion 6.x …
Description:
…Input passed to the "srch_text" parameter in "messages.php" isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability has been reported in version 6.00.109. Other versions may also be affected.
Solution:
The vulnerability has been fixed in an updated 6.00.207 version.
http://www.php-fusion.co.uk/downloads.php?cat_id=3 …"

:ph34r: