Show filters
86 Total Results
Displaying 51-60 of 86
Sort by:
Attacker Value
Unknown

CVE-2008-2227

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1918

Disclosure Date: April 23, 2008 (last updated October 04, 2023)
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.
0
Attacker Value
Unknown

CVE-2007-5187

Disclosure Date: October 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter.
0
Attacker Value
Unknown

CVE-2007-3559

Disclosure Date: July 04, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant.
0
Attacker Value
Unknown

CVE-2007-1978

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.
0
Attacker Value
Unknown

CVE-2007-1845

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.
0
Attacker Value
Unknown

CVE-2006-7003

Disclosure Date: February 12, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote attackers to execute arbitrary PHP code via a URL in the xtrphome parameter.
0
Attacker Value
Unknown

CVE-2006-4673

Disclosure Date: September 11, 2006 (last updated October 04, 2023)
Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.
0
Attacker Value
Unknown

CVE-2006-4240

Disclosure Date: August 21, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
0
Attacker Value
Unknown

CVE-2006-3555

Disclosure Date: July 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer.
0