PT-2005-1732 · Php Fusion · Php-Fusion

Firest0Rm

·

Publicado

2005-03-06

·

Atualizado

2016-10-18

·

CVE-2005-0692

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP-Fusion versions 5.x
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript. This occurs in the fusion core.php file.
Recommendations For PHP-Fusion version 5.x, update to a version that includes a fix for this issue, as using character-encoded Javascript in IMG bbcode can lead to XSS attacks. As a temporary workaround, consider restricting the use of IMG bbcode in messages to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0692

Produtos afetados

Php-Fusion