Fusetalk is a web-based community and forum platform whose vulnerability profile concentrates on a single product and reflects the application-layer input-handling challenges endemic to web-facing platforms that process user-generated content. The recurring weakness classes—SQL injection, cross-site scripting, and cross-site request forgery—are characteristic of web applications that must parse and sanitize user input while managing session state, and vulnerabilities in this vendor's disclosures have a strong tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fusetalk over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3301HIGH SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch m | Jun 20, 2007 | 7.5 | 35 | NO | YES |
CVE-2004-1995MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. | Dec 31, 2004 | 6.5 | 26 | NO | YES |
CVE-2012-5295MEDIUM Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter. | Oct 4, 2012 | 4.3 | 25 | NO | YES |
CVE-2007-3339MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject ar | Jun 21, 2007 | 4.3 | 25 | NO | YES |
CVE-2007-3705HIGH SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly oth | Jul 11, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-3273HIGH SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information | Jun 19, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fusetalk.
Media articles that mention a CVE ID that affects a product developed by Fusetalk — matched by CVE ID, not by vendor name.