PHP Fusion records
30 published records for vendor php fusion.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 13
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2004-1724Proof of concept | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wrphp fusion · php fusion | High7.5 | — | 6.9% | Aug 18, 2004 |
31Monitor | CVE-2005-3157Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_senphp fusion · php fusion | High7.5 | — | 3.6% | Oct 6, 2005 |
31Monitor | CVE-2005-3158No exploit | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands viphp fusion · php fusion | High7.5 | — | 1.8% | Oct 6, 2005 |
30Monitor | CVE-2005-3740No exploit | Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) tphp fusion · php fusion | High7.5 | — | 1.6% | Nov 22, 2005 |
30Monitor | CVE-2005-3161No exploit | Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the acphp fusion · php fusion | High7.5 | — | 1.4% | Oct 6, 2005 |
30Monitor | CVE-2005-4005Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute aphp fusion · php fusion | High7.5 | — | 1.3% | Dec 4, 2005 |
30Monitor | CVE-2007-1845Proof of concept | SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers tphp fusion · expanded calendar module | High7.5 | — | 1.2% | Apr 3, 2007 |
30Monitor | CVE-2004-2437No exploit | SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) iphp fusion · php fusion | High7.5 | — | 1.2% | Dec 31, 2004 |
30Monitor | CVE-2005-3159Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parametphp fusion · php fusion | High7.5 | — | 1.2% | Oct 6, 2005 |
30Monitor | CVE-2005-4517Proof of concept | SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratingphp fusion · php fusion | High7.5 | — | 1.2% | Dec 27, 2005 |
30Monitor | CVE-2005-3160No exploit | Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1php fusion · php fusion | High7.5 | — | 1.1% | Oct 6, 2005 |
30Monitor | CVE-2007-1978Proof of concept | SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands php fusion · arcade module | High7.5 | — | 1.0% | Apr 11, 2007 |
27Monitor | CVE-2006-2330Proof of concept | PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files ofphp fusion · php fusion | Medium6.4 | — | 7.8% | May 11, 2006 |
26Monitor | CVE-2006-2331Proof of concept | Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via php fusion · php fusion | Medium6.4 | — | 4.4% | May 11, 2006 |
26Monitor | CVE-2006-2459Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL cophp fusion · php fusion | Medium6.4 | — | 2.1% | May 19, 2006 |
23Monitor | CVE-2006-3555No exploit | Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary webphp fusion · php fusion | Medium5.8 | — | 1.3% | Jul 12, 2006 |
22Monitor | CVE-2005-2075Proof of concept | PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, whphp fusion · php fusion | Medium5.0 | — | 6.8% | Jun 29, 2005 |
21Monitor | CVE-2005-0345Proof of concept | viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protectephp fusion · php fusion | Medium5.0 | — | 2.8% | May 2, 2005 |
20Monitor | CVE-2005-3739No exploit | Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifiephp fusion · php fusion | Medium5.0 | — | 1.5% | Nov 22, 2005 |
20Monitor | CVE-2005-2401No exploit | PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.php fusion · php fusion | Medium5.0 | — | 1.3% | Jul 27, 2005 |
20Monitor | CVE-2004-1723No exploit | The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direphp fusion · php fusion | Medium5.0 | — | 1.2% | Dec 31, 2004 |
18Monitor | CVE-2006-0593No exploit | Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via thphp fusion · php fusion | Medium4.3 | — | 2.1% | Feb 7, 2006 |
18Monitor | CVE-2005-4516Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web sphp fusion · php fusion | Medium4.3 | — | 2.1% | Dec 27, 2005 |
18Monitor | CVE-2005-2783Proof of concept | Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML vphp fusion · php fusion | Medium4.3 | — | 1.8% | Sep 2, 2005 |
18Monitor | CVE-2005-0829Proof of concept | Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitraphp fusion · php fusion | Medium4.3 | — | 1.7% | May 2, 2005 |
- CVE-2004-172432Monitor
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wr
HighCVSS 7.5Proof of conceptEPSS 7%php fusion · php fusionAug 18, 2004
- CVE-2005-315731Monitor
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_sen
HighCVSS 7.5Proof of conceptEPSS 4%php fusion · php fusionOct 6, 2005
- CVE-2005-315831Monitor
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 2%php fusion · php fusionOct 6, 2005
- CVE-2005-374030Monitor
Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) t
HighCVSS 7.5No exploitEPSS 2%php fusion · php fusionNov 22, 2005
- CVE-2005-316130Monitor
Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the ac
HighCVSS 7.5No exploitEPSS 1%php fusion · php fusionOct 6, 2005
- CVE-2005-400530Monitor
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute a
HighCVSS 7.5Proof of conceptEPSS 1%php fusion · php fusionDec 4, 2005
- CVE-2007-184530Monitor
SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers t
HighCVSS 7.5Proof of conceptEPSS 1%php fusion · expanded calendar moduleApr 3, 2007
- CVE-2004-243730Monitor
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) i
HighCVSS 7.5No exploitEPSS 1%php fusion · php fusionDec 31, 2004
- CVE-2005-315930Monitor
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view paramet
HighCVSS 7.5Proof of conceptEPSS 1%php fusion · php fusionOct 6, 2005
- CVE-2005-451730Monitor
SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the rating
HighCVSS 7.5Proof of conceptEPSS 1%php fusion · php fusionDec 27, 2005
- CVE-2005-316030Monitor
Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1
HighCVSS 7.5No exploitEPSS 1%php fusion · php fusionOct 6, 2005
- CVE-2007-197830Monitor
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%php fusion · arcade moduleApr 11, 2007
- CVE-2006-233027Monitor
PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of
MediumCVSS 6.4Proof of conceptEPSS 8%php fusion · php fusionMay 11, 2006
- CVE-2006-233126Monitor
Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via
MediumCVSS 6.4Proof of conceptEPSS 4%php fusion · php fusionMay 11, 2006
- CVE-2006-245926Monitor
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL co
MediumCVSS 6.4Proof of conceptEPSS 2%php fusion · php fusionMay 19, 2006
- CVE-2006-355523Monitor
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web
MediumCVSS 5.8No exploitEPSS 1%php fusion · php fusionJul 12, 2006
- CVE-2005-207522Monitor
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, wh
MediumCVSS 5.0Proof of conceptEPSS 7%php fusion · php fusionJun 29, 2005
- CVE-2005-034521Monitor
viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protecte
MediumCVSS 5.0Proof of conceptEPSS 3%php fusion · php fusionMay 2, 2005
- CVE-2005-373920Monitor
Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifie
MediumCVSS 5.0No exploitEPSS 2%php fusion · php fusionNov 22, 2005
- CVE-2005-240120Monitor
PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.
MediumCVSS 5.0No exploitEPSS 1%php fusion · php fusionJul 27, 2005
- CVE-2004-172320Monitor
The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a dire
MediumCVSS 5.0No exploitEPSS 1%php fusion · php fusionDec 31, 2004
- CVE-2006-059318Monitor
Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via th
MediumCVSS 4.3No exploitEPSS 2%php fusion · php fusionFeb 7, 2006
- CVE-2005-451618Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web s
MediumCVSS 4.3Proof of conceptEPSS 2%php fusion · php fusionDec 27, 2005
- CVE-2005-278318Monitor
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML v
MediumCVSS 4.3Proof of conceptEPSS 2%php fusion · php fusionSep 2, 2005
- CVE-2005-082918Monitor
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitra
MediumCVSS 4.3Proof of conceptEPSS 2%php fusion · php fusionMay 2, 2005