Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Arcade Module HIGH 7.5
CVE-2007-1978

SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the c…

No fix yet
Fix from $1,950 2007-04-12
Expanded Calendar Module HIGH 7.5
CVE-2007-1845

SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute…

No fix yet
Fix from $1,950 2007-04-03
Php Fusion MEDIUM 5.8
CVE-2006-3555

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script o…

Patch available
Fix from $1,600 2006-07-13
Php Fusion MEDIUM 6.4
CVE-2006-2459

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands vi…

No fix yet
Fix from $1,600 2006-05-19
Php Fusion MEDIUM 6.4
CVE-2006-2330EPSS 8%

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrar…

Patch available
Fix from $1,600 2006-05-12
Php Fusion MEDIUM 6.4
CVE-2006-2331

Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. …

Patch available
Fix from $1,600 2006-05-12
Php Fusion HIGH 7.5
CVE-2005-4517

SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratings paramet…

Mitigation only
Fix from $1,950 2005-12-28
Php Fusion HIGH 7.5
CVE-2005-4005

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary …

No fix yet
Fix from $1,950 2005-12-05
Php Fusion HIGH 7.5
CVE-2005-3740

Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the forum_…

Fix: after 6.00.206
Fix from $1,950 2005-11-22
Php Fusion HIGH 7.5
CVE-2005-3157

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send paramet…

No fix yet
Fix from $1,950 2005-10-06
Php Fusion HIGH 7.5
CVE-2005-3158

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands via the (1)…

No fix yet
Fix from $1,950 2005-10-06
Php Fusion HIGH 7.5
CVE-2005-3160

Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1) album a…

Mitigation only
Fix from $1,950 2005-10-06
Php Fusion HIGH 7.5
CVE-2005-3161

Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate pa…

Patch available
Fix from $1,950 2005-10-06
Php Fusion MEDIUM 5.0
CVE-2005-2401

PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.

Mitigation only
Fix from $1,600 2005-07-27
Php Fusion MEDIUM 5.0
CVE-2005-2075EPSS 7%

PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allow…

Patch available
Fix from $1,600 2005-06-29
Php Fusion MEDIUM 5.0
CVE-2005-0345

viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums …

Mitigation only
Fix from $1,600 2005-05-02
Php Fusion HIGH 7.5
CVE-2004-2437

SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php …

Mitigation only
Fix from $1,950 2004-12-31
Php Fusion MEDIUM 5.0
CVE-2004-1723

The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP r…

Mitigation only
Fix from $1,600 2004-12-31
Php Fusion HIGH 7.5
CVE-2004-1724EPSS 7%

The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execu…

No fix yet
Fix from $1,950 2004-08-18