İçeriğe atla
Noroxi

PHP Fusion kayıtları

php fusion üreticisine ait 30 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
13
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

    Çubuk: toplam · koyu kısım: CISA KEV.

    Tekrar eden sınıflar

      Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

      CWE

      Tüm kayıtlar

      30 kayıt
      • CVE-2004-1724
        32İzleyin

        The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wr

        YüksekCVSS 7,5Kavram kanıtıEPSS %7

        php fusion · php fusion18 Ağu 2004

      • CVE-2005-3157
        31İzleyin

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_sen

        YüksekCVSS 7,5Kavram kanıtıEPSS %4

        php fusion · php fusion6 Eki 2005

      • CVE-2005-3158
        31İzleyin

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands vi

        YüksekCVSS 7,5İstismar yokEPSS %2

        php fusion · php fusion6 Eki 2005

      • CVE-2005-3740
        30İzleyin

        Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) t

        YüksekCVSS 7,5İstismar yokEPSS %2

        php fusion · php fusion22 Kas 2005

      • CVE-2005-3161
        30İzleyin

        Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the ac

        YüksekCVSS 7,5İstismar yokEPSS %1

        php fusion · php fusion6 Eki 2005

      • CVE-2005-4005
        30İzleyin

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute a

        YüksekCVSS 7,5Kavram kanıtıEPSS %1

        php fusion · php fusion4 Ara 2005

      • CVE-2007-1845
        30İzleyin

        SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers t

        YüksekCVSS 7,5Kavram kanıtıEPSS %1

        php fusion · expanded calendar module3 Nis 2007

      • CVE-2004-2437
        30İzleyin

        SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) i

        YüksekCVSS 7,5İstismar yokEPSS %1

        php fusion · php fusion31 Ara 2004

      • CVE-2005-3159
        30İzleyin

        SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view paramet

        YüksekCVSS 7,5Kavram kanıtıEPSS %1

        php fusion · php fusion6 Eki 2005

      • CVE-2005-4517
        30İzleyin

        SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the rating

        YüksekCVSS 7,5Kavram kanıtıEPSS %1

        php fusion · php fusion27 Ara 2005

      • CVE-2005-3160
        30İzleyin

        Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1

        YüksekCVSS 7,5İstismar yokEPSS %1

        php fusion · php fusion6 Eki 2005

      • CVE-2007-1978
        30İzleyin

        SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands

        YüksekCVSS 7,5Kavram kanıtıEPSS %1

        php fusion · arcade module11 Nis 2007

      • CVE-2006-2330
        27İzleyin

        PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of

        OrtaCVSS 6,4Kavram kanıtıEPSS %8

        php fusion · php fusion11 May 2006

      • CVE-2006-2331
        26İzleyin

        Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via

        OrtaCVSS 6,4Kavram kanıtıEPSS %4

        php fusion · php fusion11 May 2006

      • CVE-2006-2459
        26İzleyin

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL co

        OrtaCVSS 6,4Kavram kanıtıEPSS %2

        php fusion · php fusion19 May 2006

      • CVE-2006-3555
        23İzleyin

        Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web

        OrtaCVSS 5,8İstismar yokEPSS %1

        php fusion · php fusion12 Tem 2006

      • CVE-2005-2075
        22İzleyin

        PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, wh

        OrtaCVSS 5,0Kavram kanıtıEPSS %7

        php fusion · php fusion29 Haz 2005

      • CVE-2005-0345
        21İzleyin

        viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protecte

        OrtaCVSS 5,0Kavram kanıtıEPSS %3

        php fusion · php fusion2 May 2005

      • CVE-2005-3739
        20İzleyin

        Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifie

        OrtaCVSS 5,0İstismar yokEPSS %2

        php fusion · php fusion22 Kas 2005

      • CVE-2005-2401
        20İzleyin

        PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.

        OrtaCVSS 5,0İstismar yokEPSS %1

        php fusion · php fusion27 Tem 2005

      • CVE-2004-1723
        20İzleyin

        The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a dire

        OrtaCVSS 5,0İstismar yokEPSS %1

        php fusion · php fusion31 Ara 2004

      • CVE-2006-0593
        18İzleyin

        Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via th

        OrtaCVSS 4,3İstismar yokEPSS %2

        php fusion · php fusion7 Şub 2006

      • CVE-2005-4516
        18İzleyin

        Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web s

        OrtaCVSS 4,3Kavram kanıtıEPSS %2

        php fusion · php fusion27 Ara 2005

      • CVE-2005-2783
        18İzleyin

        Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML v

        OrtaCVSS 4,3Kavram kanıtıEPSS %2

        php fusion · php fusion2 Eyl 2005

      • CVE-2005-0829
        18İzleyin

        Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitra

        OrtaCVSS 4,3Kavram kanıtıEPSS %2

        php fusion · php fusion2 May 2005