PHP Fusion kayıtları
php fusion üreticisine ait 30 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tüm kayıtlar
30 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2004-1724Kavram kanıtı | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wrphp fusion · php fusion | Yüksek7,5 | — | %6,9 | 18 Ağu 2004 |
31İzleyin | CVE-2005-3157Kavram kanıtı | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_senphp fusion · php fusion | Yüksek7,5 | — | %3,6 | 6 Eki 2005 |
31İzleyin | CVE-2005-3158İstismar yok | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands viphp fusion · php fusion | Yüksek7,5 | — | %1,8 | 6 Eki 2005 |
30İzleyin | CVE-2005-3740İstismar yok | Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) tphp fusion · php fusion | Yüksek7,5 | — | %1,6 | 22 Kas 2005 |
30İzleyin | CVE-2005-3161İstismar yok | Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the acphp fusion · php fusion | Yüksek7,5 | — | %1,4 | 6 Eki 2005 |
30İzleyin | CVE-2005-4005Kavram kanıtı | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute aphp fusion · php fusion | Yüksek7,5 | — | %1,3 | 4 Ara 2005 |
30İzleyin | CVE-2007-1845Kavram kanıtı | SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers tphp fusion · expanded calendar module | Yüksek7,5 | — | %1,2 | 3 Nis 2007 |
30İzleyin | CVE-2004-2437İstismar yok | SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) iphp fusion · php fusion | Yüksek7,5 | — | %1,2 | 31 Ara 2004 |
30İzleyin | CVE-2005-3159Kavram kanıtı | SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parametphp fusion · php fusion | Yüksek7,5 | — | %1,2 | 6 Eki 2005 |
30İzleyin | CVE-2005-4517Kavram kanıtı | SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratingphp fusion · php fusion | Yüksek7,5 | — | %1,2 | 27 Ara 2005 |
30İzleyin | CVE-2005-3160İstismar yok | Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1php fusion · php fusion | Yüksek7,5 | — | %1,1 | 6 Eki 2005 |
30İzleyin | CVE-2007-1978Kavram kanıtı | SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands php fusion · arcade module | Yüksek7,5 | — | %1,0 | 11 Nis 2007 |
27İzleyin | CVE-2006-2330Kavram kanıtı | PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files ofphp fusion · php fusion | Orta6,4 | — | %7,8 | 11 May 2006 |
26İzleyin | CVE-2006-2331Kavram kanıtı | Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via php fusion · php fusion | Orta6,4 | — | %4,4 | 11 May 2006 |
26İzleyin | CVE-2006-2459Kavram kanıtı | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL cophp fusion · php fusion | Orta6,4 | — | %2,1 | 19 May 2006 |
23İzleyin | CVE-2006-3555İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary webphp fusion · php fusion | Orta5,8 | — | %1,3 | 12 Tem 2006 |
22İzleyin | CVE-2005-2075Kavram kanıtı | PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, whphp fusion · php fusion | Orta5,0 | — | %6,8 | 29 Haz 2005 |
21İzleyin | CVE-2005-0345Kavram kanıtı | viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protectephp fusion · php fusion | Orta5,0 | — | %2,8 | 2 May 2005 |
20İzleyin | CVE-2005-3739İstismar yok | Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifiephp fusion · php fusion | Orta5,0 | — | %1,5 | 22 Kas 2005 |
20İzleyin | CVE-2005-2401İstismar yok | PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.php fusion · php fusion | Orta5,0 | — | %1,3 | 27 Tem 2005 |
20İzleyin | CVE-2004-1723İstismar yok | The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direphp fusion · php fusion | Orta5,0 | — | %1,2 | 31 Ara 2004 |
18İzleyin | CVE-2006-0593İstismar yok | Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via thphp fusion · php fusion | Orta4,3 | — | %2,1 | 7 Şub 2006 |
18İzleyin | CVE-2005-4516Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web sphp fusion · php fusion | Orta4,3 | — | %2,1 | 27 Ara 2005 |
18İzleyin | CVE-2005-2783Kavram kanıtı | Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML vphp fusion · php fusion | Orta4,3 | — | %1,8 | 2 Eyl 2005 |
18İzleyin | CVE-2005-0829Kavram kanıtı | Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitraphp fusion · php fusion | Orta4,3 | — | %1,7 | 2 May 2005 |
- CVE-2004-172432İzleyin
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/wr
YüksekCVSS 7,5Kavram kanıtıEPSS %7php fusion · php fusion18 Ağu 2004
- CVE-2005-315731İzleyin
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_sen
YüksekCVSS 7,5Kavram kanıtıEPSS %4php fusion · php fusion6 Eki 2005
- CVE-2005-315831İzleyin
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5İstismar yokEPSS %2php fusion · php fusion6 Eki 2005
- CVE-2005-374030İzleyin
Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) t
YüksekCVSS 7,5İstismar yokEPSS %2php fusion · php fusion22 Kas 2005
- CVE-2005-316130İzleyin
Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the ac
YüksekCVSS 7,5İstismar yokEPSS %1php fusion · php fusion6 Eki 2005
- CVE-2005-400530İzleyin
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute a
YüksekCVSS 7,5Kavram kanıtıEPSS %1php fusion · php fusion4 Ara 2005
- CVE-2007-184530İzleyin
SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers t
YüksekCVSS 7,5Kavram kanıtıEPSS %1php fusion · expanded calendar module3 Nis 2007
- CVE-2004-243730İzleyin
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) i
YüksekCVSS 7,5İstismar yokEPSS %1php fusion · php fusion31 Ara 2004
- CVE-2005-315930İzleyin
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view paramet
YüksekCVSS 7,5Kavram kanıtıEPSS %1php fusion · php fusion6 Eki 2005
- CVE-2005-451730İzleyin
SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the rating
YüksekCVSS 7,5Kavram kanıtıEPSS %1php fusion · php fusion27 Ara 2005
- CVE-2005-316030İzleyin
Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1
YüksekCVSS 7,5İstismar yokEPSS %1php fusion · php fusion6 Eki 2005
- CVE-2007-197830İzleyin
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1php fusion · arcade module11 Nis 2007
- CVE-2006-233027İzleyin
PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of
OrtaCVSS 6,4Kavram kanıtıEPSS %8php fusion · php fusion11 May 2006
- CVE-2006-233126İzleyin
Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via
OrtaCVSS 6,4Kavram kanıtıEPSS %4php fusion · php fusion11 May 2006
- CVE-2006-245926İzleyin
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL co
OrtaCVSS 6,4Kavram kanıtıEPSS %2php fusion · php fusion19 May 2006
- CVE-2006-355523İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web
OrtaCVSS 5,8İstismar yokEPSS %1php fusion · php fusion12 Tem 2006
- CVE-2005-207522İzleyin
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, wh
OrtaCVSS 5,0Kavram kanıtıEPSS %7php fusion · php fusion29 Haz 2005
- CVE-2005-034521İzleyin
viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protecte
OrtaCVSS 5,0Kavram kanıtıEPSS %3php fusion · php fusion2 May 2005
- CVE-2005-373920İzleyin
Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecifie
OrtaCVSS 5,0İstismar yokEPSS %2php fusion · php fusion22 Kas 2005
- CVE-2005-240120İzleyin
PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.
OrtaCVSS 5,0İstismar yokEPSS %1php fusion · php fusion27 Tem 2005
- CVE-2004-172320İzleyin
The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a dire
OrtaCVSS 5,0İstismar yokEPSS %1php fusion · php fusion31 Ara 2004
- CVE-2006-059318İzleyin
Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via th
OrtaCVSS 4,3İstismar yokEPSS %2php fusion · php fusion7 Şub 2006
- CVE-2005-451618İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web s
OrtaCVSS 4,3Kavram kanıtıEPSS %2php fusion · php fusion27 Ara 2005
- CVE-2005-278318İzleyin
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 4,3Kavram kanıtıEPSS %2php fusion · php fusion2 Eyl 2005
- CVE-2005-082918İzleyin
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitra
OrtaCVSS 4,3Kavram kanıtıEPSS %2php fusion · php fusion2 May 2005