PHP-Fusion kayıtları
php-fusion üreticisine ait 62 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 20
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')21
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
62 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2020-24949Kavram kanıtı | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to thephp-fusion · php-fusion | Yüksek8,8 | — | %67,5 | 3 Eyl 2020 |
45Planlayın | CVE-2010-4931Kavram kanıtı | Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .php-fusion · php-fusion · CWE-22 | Kritik10,0 | — | %15,6 | 9 Eki 2011 |
40Planlayın | CVE-2019-12099Kavram kanıtı | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_php-fusion · php-fusion · CWE-434 | Yüksek8,8 | — | %17,2 | 14 May 2019 |
38İzleyin | CVE-2020-23754İstismar yok | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arphp-fusion · phpfusion · CWE-79 | Kritik9,6 | — | %1,6 | 2 Kas 2021 |
36İzleyin | CVE-2020-12461İstismar yok | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism.php-fusion · php-fusion · CWE-89 | Yüksek8,8 | — | %1,7 | 29 Nis 2020 |
35İzleyin | CVE-2023-2453İstismar yok | Local file Inclusion (LFI) in Forum Infusion via Directory Traversalphp-fusion · phpfusion · CWE-829 | Yüksek8,8 | — | %0,9 | 5 Eyl 2023 |
35İzleyin | CVE-2022-3152İstismar yok | Unverified Password Change in phpfusion/phpfusionphp-fusion · phpfusion · CWE-620 | Yüksek8,8 | — | %0,9 | 7 Eyl 2022 |
34İzleyin | CVE-2020-37137İstismar yok | PHP-Fusion 9.03.50 - 'panels.php' Eval Injectionphp-fusion · phpfusion · CWE-95 | Yüksek8,6 | — | %0,6 | 5 Şub 2026 |
32İzleyin | CVE-2021-3172İstismar yok | An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling fephp-fusion · php-fusion · CWE-732 | Yüksek8,1 | — | %0,6 | 17 Şub 2023 |
31İzleyin | CVE-2007-5187Kavram kanıtı | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remphp-fusion · expanded calendar module · CWE-89 | Yüksek7,5 | — | %4,2 | 3 Eki 2007 |
31İzleyin | CVE-2008-5197Kavram kanıtı | SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameterphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %4,1 | 21 Kas 2008 |
31İzleyin | CVE-2013-1803Kavram kanıtı | Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) ordphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %4,0 | 5 May 2014 |
31İzleyin | CVE-2013-7375Kavram kanıtı | SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %3,6 | 5 May 2014 |
31İzleyin | CVE-2014-8596Kavram kanıtı | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) php-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %3,3 | 17 Kas 2014 |
30İzleyin | CVE-2010-4791Kavram kanıtı | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) momarcusg · mg user fotoalbum panel · CWE-89 | Yüksek7,5 | — | %1,2 | 26 Nis 2011 |
30İzleyin | CVE-2009-0832Kavram kanıtı | SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %1,1 | 5 Mar 2009 |
30İzleyin | CVE-2008-4527Kavram kanıtı | SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQphp-fusion · recepies module · CWE-89 | Yüksek7,5 | — | %1,0 | 9 Eki 2008 |
30İzleyin | CVE-2008-5733Kavram kanıtı | SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQphp-fusion · team impact ti blog system module · CWE-89 | Yüksek7,5 | — | %1,0 | 26 Ara 2008 |
30İzleyin | CVE-2009-3119Kavram kanıtı | SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %1,0 | 9 Eyl 2009 |
30İzleyin | CVE-2008-5074Kavram kanıtı | SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL cophp-fusion · freshlinks module · CWE-89 | Yüksek7,5 | — | %1,0 | 14 Kas 2008 |
30İzleyin | CVE-2008-4521Kavram kanıtı | SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion php-fusion · world of warcraft tracker infusion module · CWE-89 | Yüksek7,5 | — | %1,0 | 9 Eki 2008 |
30İzleyin | CVE-2008-5196Kavram kanıtı | SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute php-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %1,0 | 21 Kas 2008 |
30İzleyin | CVE-2008-5946Kavram kanıtı | SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %1,0 | 22 Oca 2009 |
30İzleyin | CVE-2009-4889Kavram kanıtı | SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary Sphp-fusion · php-fusion · CWE-89 | Yüksek7,5 | — | %1,0 | 11 Haz 2010 |
29İzleyin | CVE-2021-40189İstismar yok | PHPFusion 9.03.110 is affected by a remote code execution vulnerability.php-fusion · phpfusion · CWE-434 | Yüksek7,2 | — | %1,8 | 11 Eki 2021 |
- CVE-2020-2494955Planlayın
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the
YüksekCVSS 8,8Kavram kanıtıEPSS %68php-fusion · php-fusion3 Eyl 2020
- CVE-2010-493145Planlayın
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .
KritikCVSS 10,0Kavram kanıtıEPSS %16php-fusion · php-fusion9 Eki 2011
- CVE-2019-1209940Planlayın
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_
YüksekCVSS 8,8Kavram kanıtıEPSS %17php-fusion · php-fusion14 May 2019
- CVE-2020-2375438İzleyin
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute ar
KritikCVSS 9,6İstismar yokEPSS %2php-fusion · phpfusion2 Kas 2021
- CVE-2020-1246136İzleyin
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism.
YüksekCVSS 8,8İstismar yokEPSS %2php-fusion · php-fusion29 Nis 2020
- CVE-2023-245335İzleyin
Local file Inclusion (LFI) in Forum Infusion via Directory Traversal
YüksekCVSS 8,8İstismar yokEPSS %1php-fusion · phpfusion5 Eyl 2023
- CVE-2022-315235İzleyin
Unverified Password Change in phpfusion/phpfusion
YüksekCVSS 8,8İstismar yokEPSS %1php-fusion · phpfusion7 Eyl 2022
- CVE-2020-3713734İzleyin
PHP-Fusion 9.03.50 - 'panels.php' Eval Injection
YüksekCVSS 8,6İstismar yokEPSS %1php-fusion · phpfusion5 Şub 2026
- CVE-2021-317232İzleyin
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling fe
YüksekCVSS 8,1İstismar yokEPSS %1php-fusion · php-fusion17 Şub 2023
- CVE-2007-518731İzleyin
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows rem
YüksekCVSS 7,5Kavram kanıtıEPSS %4php-fusion · expanded calendar module3 Eki 2007
- CVE-2008-519731İzleyin
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %4php-fusion · php-fusion21 Kas 2008
- CVE-2013-180331İzleyin
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) ord
YüksekCVSS 7,5Kavram kanıtıEPSS %4php-fusion · php-fusion5 May 2014
- CVE-2013-737531İzleyin
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to exec
YüksekCVSS 7,5Kavram kanıtıEPSS %4php-fusion · php-fusion5 May 2014
- CVE-2014-859631İzleyin
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1)
YüksekCVSS 7,5Kavram kanıtıEPSS %3php-fusion · php-fusion17 Kas 2014
- CVE-2010-479130İzleyin
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) mo
YüksekCVSS 7,5Kavram kanıtıEPSS %1marcusg · mg user fotoalbum panel26 Nis 2011
- CVE-2009-083230İzleyin
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · php-fusion5 Mar 2009
- CVE-2008-452730İzleyin
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · recepies module9 Eki 2008
- CVE-2008-573330İzleyin
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · team impact ti blog system module26 Ara 2008
- CVE-2009-311930İzleyin
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitr
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · php-fusion9 Eyl 2009
- CVE-2008-507430İzleyin
SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL co
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · freshlinks module14 Kas 2008
- CVE-2008-452130İzleyin
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · world of warcraft tracker infusion module9 Eki 2008
- CVE-2008-519630İzleyin
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · php-fusion21 Kas 2008
- CVE-2008-594630İzleyin
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id par
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · php-fusion22 Oca 2009
- CVE-2009-488930İzleyin
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary S
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-fusion · php-fusion11 Haz 2010
- CVE-2021-4018929İzleyin
PHPFusion 9.03.110 is affected by a remote code execution vulnerability.
YüksekCVSS 7,2İstismar yokEPSS %2php-fusion · phpfusion11 Eki 2021