Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2021-40188
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.
0
Attacker Value
Unknown
CVE-2021-40189
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-40541
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
0
Attacker Value
Unknown
CVE-2021-28280
Disclosure Date: April 29, 2021 (last updated November 28, 2024)
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
0