Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2005-2783

Disclosure Date: September 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.
0
Attacker Value
Unknown

CVE-2005-2401

Disclosure Date: July 27, 2005 (last updated February 22, 2025)
PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.
0
Attacker Value
Unknown

CVE-2005-2075

Disclosure Date: June 29, 2005 (last updated February 22, 2025)
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.
0
Attacker Value
Unknown

CVE-2005-0829

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.
0
Attacker Value
Unknown

CVE-2005-0692

Disclosure Date: March 06, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.
0
Attacker Value
Unknown

CVE-2004-2505

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.
0
Attacker Value
Unknown

CVE-2002-1700

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
0
Attacker Value
Unknown

CVE-2002-0576

Disclosure Date: June 18, 2002 (last updated February 22, 2025)
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
0
Attacker Value
Unknown

CVE-2001-1514

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.
0