Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php fusion vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-5187
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the sel parameter.
Php-fusion Expanded Calendar Module 2.01
1 EDB exploit
NA
CVE-2008-4521
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the INFO_RAID_ID parameter.
Php-fusion World Of Warcraft Tracker Infusion Module 2.0
1 EDB exploit
NA
CVE-2006-4240
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote malicious users to execute arbitrary PHP code via a URL in the fpath parameter.
Fusionphp Fusion News 3.6.1
Fusionphp Fusion News 3.7
Fusionphp Fusion News 1.0
Fusionphp Fusion News 3.3
1 EDB exploit
NA
CVE-2006-7003
PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote malicious users to execute arbitrary PHP code via a URL in the xtrphome parameter.
Fusionphp Fusion Polls
9.8
CVSSv3
CVE-2020-28904
Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and previous versions allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.
Nagios Fusion
NA
CVE-2006-3387
Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote malicious users to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code that has been inject...
Fusionphp Fusion News 1.0
1 EDB exploit
NA
CVE-2013-1805
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-2013-1806 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should referen...
1 EDB exploit
NA
CVE-2020-356871
PHP-Fusion version 9.03.90 suffers from a cross site request forgery vulnerability.
NA
CVE-2009-3119
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the view_id parameter.
X-iweb.ru Download System Msf
1 EDB exploit
NA
CVE-2005-3159
SQL injection vulnerability in messages.php in PHP-Fusion allows remote malicious users to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »