PT-2007-4817 · Php Fusion · Php-Fusion
Nights_Shadow
·
Published
2007-07-04
·
Updated
2017-07-29
·
CVE-2007-3559
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Fusion versions 6.01.9 through 6.01.10
Description
The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote authenticated users to inject arbitrary web script or HTML via the URI when guest posts are enabled. This is related to the FUSION QUERY constant.
Recommendations
For PHP-Fusion versions 6.01.9 through 6.01.10, consider disabling guest posts in the shoutbox panel to minimize the risk of exploitation until a patch is available. Restrict access to the infusions/shoutbox panel/shoutbox panel.php file to prevent malicious injections.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Fusion