Vulnerabilities > PHP Fusion > PHP Fusion > 6.0.105
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-09-11 | CVE-2006-4673 | SQL Injection vulnerability in PHP-Fusion News.PHP Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php. | 2.6 |
2006-07-13 | CVE-2006-3555 | HTML Injection vulnerability in PHP-Fusion Avatar Image Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer. network php-fusion | 5.8 |
2005-09-02 | CVE-2005-2783 | Unspecified vulnerability in PHP Fusion PHP Fusion Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags. network php-fusion | 4.3 |
2005-07-27 | CVE-2005-2401 | Unspecified vulnerability in PHP Fusion PHP Fusion PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag. | 5.0 |