PHP-Fusion

PHP-Fusion is a light-weight open-source content management system (CMS) written in PHP 5. It utilises a MySQL database to store your site content and includes a simple comprehensive administration system. PHP-Fusion includes the most common features you would expect to see in many other CMS packages.

Severity Summary:

High: 9 Medium: 24 Low: 1
Reference
Title
Severity
PHPFusion Multiple SQL Injection Vulnerabilities
High
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
PHPFusion Code Execution Vulnerability
High
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
PHP-Fusion Incorrect Permission Assignment for Critical Resource Vulnerability
High
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
PHP-Fusion Improper Privilege Management Vulnerability
High
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Authentication Bypass by Capture-replay Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion URL Redirection to Untrusted Site (Open Redirect) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium