CVE-2012-6043
- EPSS 1.63%
- Veröffentlicht 26.11.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:47:42
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
- EPSS 16.4%
- Veröffentlicht 09.10.2011 10:55:21
- Zuletzt bearbeitet 16.06.2026 23:25:49
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party
CVE-2008-6850
- EPSS 1.07%
- Veröffentlicht 07.07.2009 19:00:00
- Zuletzt bearbeitet 16.06.2026 23:03:06
Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion 6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2008-5946
- EPSS 0.96%
- Veröffentlicht 22.01.2009 11:30:05
- Zuletzt bearbeitet 16.06.2026 23:01:17
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
CVE-2008-5335
- EPSS 2.88%
- Veröffentlicht 05.12.2008 01:30:00
- Zuletzt bearbeitet 16.06.2026 22:59:44
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157,...
CVE-2008-5197
- EPSS 4.1%
- Veröffentlicht 21.11.2008 17:30:00
- Zuletzt bearbeitet 16.06.2026 22:59:26
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.
- EPSS 1.49%
- Veröffentlicht 23.04.2008 13:05:00
- Zuletzt bearbeitet 16.06.2026 22:52:44
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] paramete...
CVE-2007-3559
- EPSS 0.87%
- Veröffentlicht 04.07.2007 16:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:17
Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to t...