PHP-Fusion SUBMIT.PHP HTML Injection Vulnerabilities
BID:14066
Info
PHP-Fusion SUBMIT.PHP HTML Injection Vulnerabilities
| Bugtraq ID: | 14066 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2005 12:00AM |
| Updated: | Jun 27 2005 12:00AM |
| Credit: | Discovery is credited to Easyex. |
| Vulnerable: |
PHP-Fusion PHP-Fusion 6.0.105 |
| Not Vulnerable: | |
Discussion
PHP-Fusion SUBMIT.PHP HTML Injection Vulnerabilities
PHP-Fusion is susceptible to HTML injection vulnerabilities affecting the 'submit.php' script.
These issues may allow an attacker to inject malicious HTML and script code into the vulnerable application. An unsuspecting user or administrator viewing the resulting pages will have the attacker-supplied script code executed within their browser in the context of the vulnerable Web site.
PHP-Fusion is susceptible to HTML injection vulnerabilities affecting the 'submit.php' script.
These issues may allow an attacker to inject malicious HTML and script code into the vulnerable application. An unsuspecting user or administrator viewing the resulting pages will have the attacker-supplied script code executed within their browser in the context of the vulnerable Web site.
Exploit / POC
PHP-Fusion SUBMIT.PHP HTML Injection Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
PHP-Fusion SUBMIT.PHP HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Fusion SUBMIT.PHP HTML Injection Vulnerabilities
References:
References:
- PHP Fusion - Cross site scripting. (Easyex)
- PHP-Fusion Homepage (PHP-Fusion)