CVE-2013-1807: PHP-Fusion

Medium severity, CVSS 5.0. EPSS: 7.6% chance of exploitation in the next 30 days.

PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

Affected products

  • PHP-Fusion PHP-Fusion: up to and including 7.02.05; version 7.02.01 only; version 7.02.02 only; version 7.02.03 only; version 7.02.04 only

Published 2014-04-30. Last modified 2026-06-16.