Записи PHP Fusion
30 опубликованных записей вендора php fusion.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
30 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2004-1724Proof of concept | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wrphp fusion · php fusion | Высокая7,5 | — | 6,9 % | 18 авг. 2004 г. |
31Наблюдать | CVE-2005-3157Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_senphp fusion · php fusion | Высокая7,5 | — | 3,6 % | 6 окт. 2005 г. |
31Наблюдать | CVE-2005-3158Эксплойта нет | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands viphp fusion · php fusion | Высокая7,5 | — | 1,8 % | 6 окт. 2005 г. |
30Наблюдать | CVE-2005-3740Эксплойта нет | Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) tphp fusion · php fusion | Высокая7,5 | — | 1,6 % | 22 нояб. 2005 г. |
30Наблюдать | CVE-2005-3161Эксплойта нет | Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the acphp fusion · php fusion | Высокая7,5 | — | 1,4 % | 6 окт. 2005 г. |
30Наблюдать | CVE-2005-4005Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute aphp fusion · php fusion | Высокая7,5 | — | 1,3 % | 4 дек. 2005 г. |
30Наблюдать | CVE-2007-1845Proof of concept | SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers tphp fusion · expanded calendar module | Высокая7,5 | — | 1,2 % | 3 апр. 2007 г. |
30Наблюдать | CVE-2004-2437Эксплойта нет | SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) iphp fusion · php fusion | Высокая7,5 | — | 1,2 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2005-3159Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parametphp fusion · php fusion | Высокая7,5 | — | 1,2 % | 6 окт. 2005 г. |
30Наблюдать | CVE-2005-4517Proof of concept | SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratingphp fusion · php fusion | Высокая7,5 | — | 1,2 % | 27 дек. 2005 г. |
30Наблюдать | CVE-2005-3160Эксплойта нет | Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1php fusion · php fusion | Высокая7,5 | — | 1,1 % | 6 окт. 2005 г. |
30Наблюдать | CVE-2007-1978Proof of concept | SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands php fusion · arcade module | Высокая7,5 | — | 1,0 % | 11 апр. 2007 г. |
27Наблюдать | CVE-2006-2330Proof of concept | PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files ofphp fusion · php fusion | Средняя6,4 | — | 7,8 % | 11 мая 2006 г. |
26Наблюдать | CVE-2006-2331Proof of concept | Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via php fusion · php fusion | Средняя6,4 | — | 4,4 % | 11 мая 2006 г. |
26Наблюдать | CVE-2006-2459Proof of concept | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL cophp fusion · php fusion | Средняя6,4 | — | 2,1 % | 19 мая 2006 г. |
23Наблюдать | CVE-2006-3555Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary webphp fusion · php fusion | Средняя5,8 | — | 1,3 % | 12 июл. 2006 г. |
22Наблюдать | CVE-2005-2075Proof of concept | PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, whphp fusion · php fusion | Средняя5,0 | — | 6,8 % | 29 июн. 2005 г. |
21Наблюдать | CVE-2005-0345Proof of concept | viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protectephp fusion · php fusion | Средняя5,0 | — | 2,8 % | 2 мая 2005 г. |
20Наблюдать | CVE-2005-3739Эксплойта нет | Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifiephp fusion · php fusion | Средняя5,0 | — | 1,5 % | 22 нояб. 2005 г. |
20Наблюдать | CVE-2005-2401Эксплойта нет | PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.php fusion · php fusion | Средняя5,0 | — | 1,3 % | 27 июл. 2005 г. |
20Наблюдать | CVE-2004-1723Эксплойта нет | The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direphp fusion · php fusion | Средняя5,0 | — | 1,2 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2006-0593Эксплойта нет | Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via thphp fusion · php fusion | Средняя4,3 | — | 2,1 % | 7 февр. 2006 г. |
18Наблюдать | CVE-2005-4516Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web sphp fusion · php fusion | Средняя4,3 | — | 2,1 % | 27 дек. 2005 г. |
18Наблюдать | CVE-2005-2783Proof of concept | Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML vphp fusion · php fusion | Средняя4,3 | — | 1,8 % | 2 сент. 2005 г. |
18Наблюдать | CVE-2005-0829Proof of concept | Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitraphp fusion · php fusion | Средняя4,3 | — | 1,7 % | 2 мая 2005 г. |
- CVE-2004-172432Наблюдать
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wr
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %php fusion · php fusion18 авг. 2004 г.
- CVE-2005-315731Наблюдать
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_sen
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %php fusion · php fusion6 окт. 2005 г.
- CVE-2005-315831Наблюдать
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %php fusion · php fusion6 окт. 2005 г.
- CVE-2005-374030Наблюдать
Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %php fusion · php fusion22 нояб. 2005 г.
- CVE-2005-316130Наблюдать
Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the ac
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php fusion · php fusion6 окт. 2005 г.
- CVE-2005-400530Наблюдать
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute a
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php fusion · php fusion4 дек. 2005 г.
- CVE-2007-184530Наблюдать
SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers t
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php fusion · expanded calendar module3 апр. 2007 г.
- CVE-2004-243730Наблюдать
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) i
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php fusion · php fusion31 дек. 2004 г.
- CVE-2005-315930Наблюдать
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php fusion · php fusion6 окт. 2005 г.
- CVE-2005-451730Наблюдать
SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the rating
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php fusion · php fusion27 дек. 2005 г.
- CVE-2005-316030Наблюдать
Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php fusion · php fusion6 окт. 2005 г.
- CVE-2007-197830Наблюдать
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php fusion · arcade module11 апр. 2007 г.
- CVE-2006-233027Наблюдать
PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of
СредняяCVSS 6,4Proof of conceptEPSS 8 %php fusion · php fusion11 мая 2006 г.
- CVE-2006-233126Наблюдать
Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via
СредняяCVSS 6,4Proof of conceptEPSS 4 %php fusion · php fusion11 мая 2006 г.
- CVE-2006-245926Наблюдать
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL co
СредняяCVSS 6,4Proof of conceptEPSS 2 %php fusion · php fusion19 мая 2006 г.
- CVE-2006-355523Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web
СредняяCVSS 5,8Эксплойта нетEPSS 1 %php fusion · php fusion12 июл. 2006 г.
- CVE-2005-207522Наблюдать
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, wh
СредняяCVSS 5,0Proof of conceptEPSS 7 %php fusion · php fusion29 июн. 2005 г.
- CVE-2005-034521Наблюдать
viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protecte
СредняяCVSS 5,0Proof of conceptEPSS 3 %php fusion · php fusion2 мая 2005 г.
- CVE-2005-373920Наблюдать
Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifie
СредняяCVSS 5,0Эксплойта нетEPSS 2 %php fusion · php fusion22 нояб. 2005 г.
- CVE-2005-240120Наблюдать
PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %php fusion · php fusion27 июл. 2005 г.
- CVE-2004-172320Наблюдать
The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a dire
СредняяCVSS 5,0Эксплойта нетEPSS 1 %php fusion · php fusion31 дек. 2004 г.
- CVE-2006-059318Наблюдать
Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via th
СредняяCVSS 4,3Эксплойта нетEPSS 2 %php fusion · php fusion7 февр. 2006 г.
- CVE-2005-451618Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web s
СредняяCVSS 4,3Proof of conceptEPSS 2 %php fusion · php fusion27 дек. 2005 г.
- CVE-2005-278318Наблюдать
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML v
СредняяCVSS 4,3Proof of conceptEPSS 2 %php fusion · php fusion2 сент. 2005 г.
- CVE-2005-082918Наблюдать
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitra
СредняяCVSS 4,3Proof of conceptEPSS 2 %php fusion · php fusion2 мая 2005 г.