Перейти к содержимому
Noroxi

Записи PHP Fusion

30 опубликованных записей вендора php fusion.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
13
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

      Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

      CWE

      Все записи

      30 записей
      • CVE-2004-1724
        32Наблюдать

        The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wr

        ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

        php fusion · php fusion18 авг. 2004 г.

      • CVE-2005-3157
        31Наблюдать

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_sen

        ВысокаяCVSS 7,5Proof of conceptEPSS 4 %

        php fusion · php fusion6 окт. 2005 г.

      • CVE-2005-3158
        31Наблюдать

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands vi

        ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

        php fusion · php fusion6 окт. 2005 г.

      • CVE-2005-3740
        30Наблюдать

        Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) t

        ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

        php fusion · php fusion22 нояб. 2005 г.

      • CVE-2005-3161
        30Наблюдать

        Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the ac

        ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

        php fusion · php fusion6 окт. 2005 г.

      • CVE-2005-4005
        30Наблюдать

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute a

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php fusion · php fusion4 дек. 2005 г.

      • CVE-2007-1845
        30Наблюдать

        SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers t

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php fusion · expanded calendar module3 апр. 2007 г.

      • CVE-2004-2437
        30Наблюдать

        SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) i

        ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

        php fusion · php fusion31 дек. 2004 г.

      • CVE-2005-3159
        30Наблюдать

        SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view paramet

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php fusion · php fusion6 окт. 2005 г.

      • CVE-2005-4517
        30Наблюдать

        SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the rating

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php fusion · php fusion27 дек. 2005 г.

      • CVE-2005-3160
        30Наблюдать

        Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1

        ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

        php fusion · php fusion6 окт. 2005 г.

      • CVE-2007-1978
        30Наблюдать

        SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php fusion · arcade module11 апр. 2007 г.

      • CVE-2006-2330
        27Наблюдать

        PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of

        СредняяCVSS 6,4Proof of conceptEPSS 8 %

        php fusion · php fusion11 мая 2006 г.

      • CVE-2006-2331
        26Наблюдать

        Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via

        СредняяCVSS 6,4Proof of conceptEPSS 4 %

        php fusion · php fusion11 мая 2006 г.

      • CVE-2006-2459
        26Наблюдать

        SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL co

        СредняяCVSS 6,4Proof of conceptEPSS 2 %

        php fusion · php fusion19 мая 2006 г.

      • CVE-2006-3555
        23Наблюдать

        Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web

        СредняяCVSS 5,8Эксплойта нетEPSS 1 %

        php fusion · php fusion12 июл. 2006 г.

      • CVE-2005-2075
        22Наблюдать

        PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, wh

        СредняяCVSS 5,0Proof of conceptEPSS 7 %

        php fusion · php fusion29 июн. 2005 г.

      • CVE-2005-0345
        21Наблюдать

        viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protecte

        СредняяCVSS 5,0Proof of conceptEPSS 3 %

        php fusion · php fusion2 мая 2005 г.

      • CVE-2005-3739
        20Наблюдать

        Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifie

        СредняяCVSS 5,0Эксплойта нетEPSS 2 %

        php fusion · php fusion22 нояб. 2005 г.

      • CVE-2005-2401
        20Наблюдать

        PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        php fusion · php fusion27 июл. 2005 г.

      • CVE-2004-1723
        20Наблюдать

        The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a dire

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        php fusion · php fusion31 дек. 2004 г.

      • CVE-2006-0593
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via th

        СредняяCVSS 4,3Эксплойта нетEPSS 2 %

        php fusion · php fusion7 февр. 2006 г.

      • CVE-2005-4516
        18Наблюдать

        Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web s

        СредняяCVSS 4,3Proof of conceptEPSS 2 %

        php fusion · php fusion27 дек. 2005 г.

      • CVE-2005-2783
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML v

        СредняяCVSS 4,3Proof of conceptEPSS 2 %

        php fusion · php fusion2 сент. 2005 г.

      • CVE-2005-0829
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitra

        СредняяCVSS 4,3Proof of conceptEPSS 2 %

        php fusion · php fusion2 мая 2005 г.