PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
We have discovered 86 live websites that are affected by CVE-2020-35687.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 86 live websites (48% of PHPFusion install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 13 versions ( 65% of all versions) |
| 14 websites | |
| 16 websites | |
| 14 websites | |
| 12 websites | |
| 12 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites |
| .eu | 13 websites |
| .com | 12 websites |
| .de | 10 websites |
| .pl | 8 websites |
| .nl | 8 websites |
| .org | 7 websites |
| .co.uk | 5 websites |
| .dk | 4 websites |
| .info | 2 websites |
| .net | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.****.org | *,***,*** | ||
| *********.org | *,***,*** | ||
| *******.***.la | *,***,*** | ||
| **********.**.uk | *,***,*** | ||
| *********.com | *,***,*** | ||
| ******.ro | *,***,*** | ||
| *********.pl | *,***,*** | ||
| **********.eu | *,***,*** | ||
| ********.*******.eu | *,***,*** | ||
| ***.************.nl | *,***,*** |