Skip to content
Noroxi

PHP Fusion records

30 published records for vendor php fusion.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
13
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      30 records
      • CVE-2004-1724
        32Monitor

        The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wr

        HighCVSS 7.5Proof of conceptEPSS 7%

        php fusion · php fusionAug 18, 2004

      • CVE-2005-3157
        31Monitor

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_sen

        HighCVSS 7.5Proof of conceptEPSS 4%

        php fusion · php fusionOct 6, 2005

      • CVE-2005-3158
        31Monitor

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands vi

        HighCVSS 7.5No exploitEPSS 2%

        php fusion · php fusionOct 6, 2005

      • CVE-2005-3740
        30Monitor

        Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) t

        HighCVSS 7.5No exploitEPSS 2%

        php fusion · php fusionNov 22, 2005

      • CVE-2005-3161
        30Monitor

        Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the ac

        HighCVSS 7.5No exploitEPSS 1%

        php fusion · php fusionOct 6, 2005

      • CVE-2005-4005
        30Monitor

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute a

        HighCVSS 7.5Proof of conceptEPSS 1%

        php fusion · php fusionDec 4, 2005

      • CVE-2007-1845
        30Monitor

        SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers t

        HighCVSS 7.5Proof of conceptEPSS 1%

        php fusion · expanded calendar moduleApr 3, 2007

      • CVE-2004-2437
        30Monitor

        SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) i

        HighCVSS 7.5No exploitEPSS 1%

        php fusion · php fusionDec 31, 2004

      • CVE-2005-3159
        30Monitor

        SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view paramet

        HighCVSS 7.5Proof of conceptEPSS 1%

        php fusion · php fusionOct 6, 2005

      • CVE-2005-4517
        30Monitor

        SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the rating

        HighCVSS 7.5Proof of conceptEPSS 1%

        php fusion · php fusionDec 27, 2005

      • CVE-2005-3160
        30Monitor

        Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1

        HighCVSS 7.5No exploitEPSS 1%

        php fusion · php fusionOct 6, 2005

      • CVE-2007-1978
        30Monitor

        SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands

        HighCVSS 7.5Proof of conceptEPSS 1%

        php fusion · arcade moduleApr 11, 2007

      • CVE-2006-2330
        27Monitor

        PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of

        MediumCVSS 6.4Proof of conceptEPSS 8%

        php fusion · php fusionMay 11, 2006

      • CVE-2006-2331
        26Monitor

        Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via

        MediumCVSS 6.4Proof of conceptEPSS 4%

        php fusion · php fusionMay 11, 2006

      • CVE-2006-2459
        26Monitor

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL co

        MediumCVSS 6.4Proof of conceptEPSS 2%

        php fusion · php fusionMay 19, 2006

      • CVE-2006-3555
        23Monitor

        Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web

        MediumCVSS 5.8No exploitEPSS 1%

        php fusion · php fusionJul 12, 2006

      • CVE-2005-2075
        22Monitor

        PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, wh

        MediumCVSS 5.0Proof of conceptEPSS 7%

        php fusion · php fusionJun 29, 2005

      • CVE-2005-0345
        21Monitor

        viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protecte

        MediumCVSS 5.0Proof of conceptEPSS 3%

        php fusion · php fusionMay 2, 2005

      • CVE-2005-3739
        20Monitor

        Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifie

        MediumCVSS 5.0No exploitEPSS 2%

        php fusion · php fusionNov 22, 2005

      • CVE-2005-2401
        20Monitor

        PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.

        MediumCVSS 5.0No exploitEPSS 1%

        php fusion · php fusionJul 27, 2005

      • CVE-2004-1723
        20Monitor

        The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a dire

        MediumCVSS 5.0No exploitEPSS 1%

        php fusion · php fusionDec 31, 2004

      • CVE-2006-0593
        18Monitor

        Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via th

        MediumCVSS 4.3No exploitEPSS 2%

        php fusion · php fusionFeb 7, 2006

      • CVE-2005-4516
        18Monitor

        Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web s

        MediumCVSS 4.3Proof of conceptEPSS 2%

        php fusion · php fusionDec 27, 2005

      • CVE-2005-2783
        18Monitor

        Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML v

        MediumCVSS 4.3Proof of conceptEPSS 2%

        php fusion · php fusionSep 2, 2005

      • CVE-2005-0829
        18Monitor

        Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitra

        MediumCVSS 4.3Proof of conceptEPSS 2%

        php fusion · php fusionMay 2, 2005