Php-fusion

Php-fusion

36 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Published 07.07.2009 19:00:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion 6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploit
  • EPSS 0.11%
  • Published 22.01.2009 11:30:05
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

Exploit
  • EPSS 0.82%
  • Published 05.12.2008 01:30:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157,...

Exploit
  • EPSS 0.36%
  • Published 21.11.2008 17:30:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.

Exploit
  • EPSS 2.36%
  • Published 23.04.2008 13:05:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] paramete...

  • EPSS 0.25%
  • Published 04.07.2007 16:30:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to t...