RSS   Vulnerabilities for 'Phpfusion'   RSS

2022-02-17
 
CVE-2014-8597

CWE-79
 

 
A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

 
2021-11-02
 
CVE-2020-23754

CWE-79
 

 
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.

 
2021-10-11
 
CVE-2021-40188

CWE-434
 

 
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.

 
 
CVE-2021-40189

CWE-434
 

 
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.

 
 
CVE-2021-40541

CWE-79
 

 
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.

 
2021-01-13
 
CVE-2020-35687

CWE-352
 

 
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

 

 >>> Vendor: Php-fusion 10 Products
Php-fusion
Expanded calendar module
Forum rank system
World of warcraft tracker infusion module
Recepies module
Freshlinks module
The kroax module
Team impact ti blog system module
Members cv module
Phpfusion


Copyright 2024, cxsecurity.com

 

Back to Top