Записи PHP-Fusion
62 опубликованных записей вендора php-fusion.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 20
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')21
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
62 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2020-24949Proof of concept | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to thephp-fusion · php-fusion | Высокая8,8 | — | 67,5 % | 3 сент. 2020 г. |
45В плане | CVE-2010-4931Proof of concept | Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .php-fusion · php-fusion · CWE-22 | Критическая10,0 | — | 15,6 % | 9 окт. 2011 г. |
40В плане | CVE-2019-12099Proof of concept | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_php-fusion · php-fusion · CWE-434 | Высокая8,8 | — | 17,2 % | 14 мая 2019 г. |
38Наблюдать | CVE-2020-23754Эксплойта нет | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arphp-fusion · phpfusion · CWE-79 | Критическая9,6 | — | 1,6 % | 2 нояб. 2021 г. |
36Наблюдать | CVE-2020-12461Эксплойта нет | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism.php-fusion · php-fusion · CWE-89 | Высокая8,8 | — | 1,7 % | 29 апр. 2020 г. |
35Наблюдать | CVE-2023-2453Эксплойта нет | Local file Inclusion (LFI) in Forum Infusion via Directory Traversalphp-fusion · phpfusion · CWE-829 | Высокая8,8 | — | 0,9 % | 5 сент. 2023 г. |
35Наблюдать | CVE-2022-3152Эксплойта нет | Unverified Password Change in phpfusion/phpfusionphp-fusion · phpfusion · CWE-620 | Высокая8,8 | — | 0,9 % | 7 сент. 2022 г. |
34Наблюдать | CVE-2020-37137Эксплойта нет | PHP-Fusion 9.03.50 - 'panels.php' Eval Injectionphp-fusion · phpfusion · CWE-95 | Высокая8,6 | — | 0,6 % | 5 февр. 2026 г. |
32Наблюдать | CVE-2021-3172Эксплойта нет | An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling fephp-fusion · php-fusion · CWE-732 | Высокая8,1 | — | 0,6 % | 17 февр. 2023 г. |
31Наблюдать | CVE-2007-5187Proof of concept | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remphp-fusion · expanded calendar module · CWE-89 | Высокая7,5 | — | 4,2 % | 3 окт. 2007 г. |
31Наблюдать | CVE-2008-5197Proof of concept | SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameterphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 4,1 % | 21 нояб. 2008 г. |
31Наблюдать | CVE-2013-1803Proof of concept | Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) ordphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 4,0 % | 5 мая 2014 г. |
31Наблюдать | CVE-2013-7375Proof of concept | SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 3,6 % | 5 мая 2014 г. |
31Наблюдать | CVE-2014-8596Proof of concept | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) php-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 3,3 % | 17 нояб. 2014 г. |
30Наблюдать | CVE-2010-4791Proof of concept | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) momarcusg · mg user fotoalbum panel · CWE-89 | Высокая7,5 | — | 1,2 % | 26 апр. 2011 г. |
30Наблюдать | CVE-2009-0832Proof of concept | SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 1,1 % | 5 мар. 2009 г. |
30Наблюдать | CVE-2008-4527Proof of concept | SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQphp-fusion · recepies module · CWE-89 | Высокая7,5 | — | 1,0 % | 9 окт. 2008 г. |
30Наблюдать | CVE-2008-5733Proof of concept | SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQphp-fusion · team impact ti blog system module · CWE-89 | Высокая7,5 | — | 1,0 % | 26 дек. 2008 г. |
30Наблюдать | CVE-2009-3119Proof of concept | SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 1,0 % | 9 сент. 2009 г. |
30Наблюдать | CVE-2008-5074Proof of concept | SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL cophp-fusion · freshlinks module · CWE-89 | Высокая7,5 | — | 1,0 % | 14 нояб. 2008 г. |
30Наблюдать | CVE-2008-4521Proof of concept | SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion php-fusion · world of warcraft tracker infusion module · CWE-89 | Высокая7,5 | — | 1,0 % | 9 окт. 2008 г. |
30Наблюдать | CVE-2008-5196Proof of concept | SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute php-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 1,0 % | 21 нояб. 2008 г. |
30Наблюдать | CVE-2008-5946Proof of concept | SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 1,0 % | 22 янв. 2009 г. |
30Наблюдать | CVE-2009-4889Proof of concept | SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary Sphp-fusion · php-fusion · CWE-89 | Высокая7,5 | — | 1,0 % | 11 июн. 2010 г. |
29Наблюдать | CVE-2021-40189Эксплойта нет | PHPFusion 9.03.110 is affected by a remote code execution vulnerability.php-fusion · phpfusion · CWE-434 | Высокая7,2 | — | 1,8 % | 11 окт. 2021 г. |
- CVE-2020-2494955В плане
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the
ВысокаяCVSS 8,8Proof of conceptEPSS 68 %php-fusion · php-fusion3 сент. 2020 г.
- CVE-2010-493145В плане
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .
КритическаяCVSS 10,0Proof of conceptEPSS 16 %php-fusion · php-fusion9 окт. 2011 г.
- CVE-2019-1209940В плане
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %php-fusion · php-fusion14 мая 2019 г.
- CVE-2020-2375438Наблюдать
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute ar
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %php-fusion · phpfusion2 нояб. 2021 г.
- CVE-2020-1246136Наблюдать
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %php-fusion · php-fusion29 апр. 2020 г.
- CVE-2023-245335Наблюдать
Local file Inclusion (LFI) in Forum Infusion via Directory Traversal
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %php-fusion · phpfusion5 сент. 2023 г.
- CVE-2022-315235Наблюдать
Unverified Password Change in phpfusion/phpfusion
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %php-fusion · phpfusion7 сент. 2022 г.
- CVE-2020-3713734Наблюдать
PHP-Fusion 9.03.50 - 'panels.php' Eval Injection
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %php-fusion · phpfusion5 февр. 2026 г.
- CVE-2021-317232Наблюдать
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling fe
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %php-fusion · php-fusion17 февр. 2023 г.
- CVE-2007-518731Наблюдать
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows rem
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %php-fusion · expanded calendar module3 окт. 2007 г.
- CVE-2008-519731Наблюдать
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %php-fusion · php-fusion21 нояб. 2008 г.
- CVE-2013-180331Наблюдать
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) ord
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %php-fusion · php-fusion5 мая 2014 г.
- CVE-2013-737531Наблюдать
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to exec
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %php-fusion · php-fusion5 мая 2014 г.
- CVE-2014-859631Наблюдать
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %php-fusion · php-fusion17 нояб. 2014 г.
- CVE-2010-479130Наблюдать
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) mo
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %marcusg · mg user fotoalbum panel26 апр. 2011 г.
- CVE-2009-083230Наблюдать
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · php-fusion5 мар. 2009 г.
- CVE-2008-452730Наблюдать
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · recepies module9 окт. 2008 г.
- CVE-2008-573330Наблюдать
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · team impact ti blog system module26 дек. 2008 г.
- CVE-2009-311930Наблюдать
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · php-fusion9 сент. 2009 г.
- CVE-2008-507430Наблюдать
SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL co
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · freshlinks module14 нояб. 2008 г.
- CVE-2008-452130Наблюдать
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · world of warcraft tracker infusion module9 окт. 2008 г.
- CVE-2008-519630Наблюдать
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · php-fusion21 нояб. 2008 г.
- CVE-2008-594630Наблюдать
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id par
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · php-fusion22 янв. 2009 г.
- CVE-2009-488930Наблюдать
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary S
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-fusion · php-fusion11 июн. 2010 г.
- CVE-2021-4018929Наблюдать
PHPFusion 9.03.110 is affected by a remote code execution vulnerability.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %php-fusion · phpfusion11 окт. 2021 г.