Total
3 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-4240 | 1 Fusionphp | 1 Fusion News | 2024-11-21 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. | |||||
CVE-2006-3387 | 1 Fusionphp | 1 Fusion News | 2024-11-21 | 5.1 MEDIUM | N/A |
Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code that has been injected into a log file. | |||||
CVE-2004-1703 | 1 Fusionphp | 1 Fusion News | 2024-11-20 | 7.5 HIGH | 8.8 HIGH |
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag. |