PHP-Fusion BBcode Color Tag Code Injection Vulnerability
BID:14332
Info
PHP-Fusion BBcode Color Tag Code Injection Vulnerability
| Bugtraq ID: | 14332 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2005 12:00AM |
| Updated: | Jul 20 2005 12:00AM |
| Credit: | Grindordie is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP-Fusion PHP-Fusion 6.0.105 PHP-Fusion PHP-Fusion 6.0 .106 PHP-Fusion PHP-Fusion 5.0 1 Service Pack PHP-Fusion PHP-Fusion 5.0 PHP-Fusion PHP-Fusion 4.0 1 PHP-Fusion PHP-Fusion 4.00 |
| Not Vulnerable: | |
Discussion
PHP-Fusion BBcode Color Tag Code Injection Vulnerability
PHPFusion fails to properly sanitize BBCode '[color]' tags in message posts. This issue can be exploited to inject certain CSS (Cascading Style Sheet) code.
Exploitation of this vulnerability may allow an attacker to manipulate content or launch other attacks.
PHPFusion fails to properly sanitize BBCode '[color]' tags in message posts. This issue can be exploited to inject certain CSS (Cascading Style Sheet) code.
Exploitation of this vulnerability may allow an attacker to manipulate content or launch other attacks.
Exploit / POC
PHP-Fusion BBcode Color Tag Code Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PHP-Fusion BBcode Color Tag Code Injection Vulnerability
Solution:
The vendor has stated that a patch will be supplied in the near future. Users of affected packages should watch http://www.php-fusion.co.uk/ for updates.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has stated that a patch will be supplied in the near future. Users of affected packages should watch http://www.php-fusion.co.uk/ for updates.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Fusion BBcode Color Tag Code Injection Vulnerability
References:
References:
- PHP-Fusion Homepage (PHP-Fusion)