PHP-Fusion Multiple Cross-Site Scripting Vulnerabilities
BID:16548
Info
PHP-Fusion Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 16548 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0593 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2006 12:00AM |
| Updated: | Feb 08 2006 09:23PM |
| Credit: | saxible is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
PHP-Fusion PHP-Fusion 6.0.204 PHP-Fusion PHP-Fusion 6.0.110 PHP-Fusion PHP-Fusion 6.0.109 PHP-Fusion PHP-Fusion 6.0.107 PHP-Fusion PHP-Fusion 6.0.105 PHP-Fusion PHP-Fusion 6.0 303 PHP-Fusion PHP-Fusion 6.0 0.3 PHP-Fusion PHP-Fusion 6.0 .206 PHP-Fusion PHP-Fusion 6.0 .106 PHP-Fusion PHP-Fusion 5.0 1 Service Pack PHP-Fusion PHP-Fusion 5.0 PHP-Fusion PHP-Fusion 4.0 1 PHP-Fusion PHP-Fusion 4.00 |
| Not Vulnerable: |
PHP-Fusion PHP-Fusion 6.0 304 |
Discussion
PHP-Fusion Multiple Cross-Site Scripting Vulnerabilities
PHP-Fusion is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Versions 6.00.303 and prior are vulnerable; other versions may also be affected.
PHP-Fusion is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Versions 6.00.303 and prior are vulnerable; other versions may also be affected.
Exploit / POC
PHP-Fusion Multiple Cross-Site Scripting Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
PHP-Fusion Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released version 6.00.304 to address this issue; please see the reference section for further details.
PHP-Fusion PHP-Fusion 6.0 303
Solution:
The vendor has released version 6.00.304 to address this issue; please see the reference section for further details.
PHP-Fusion PHP-Fusion 6.0 303
-
PHP-Fusion php-fusion-6.00.304.zip
PHP-Fusion 6.00.304 fixing PHP-Fusion 6.00.303
http://ovh.dl.sourceforge.net/sourceforge/php-fusion/php-fusion-6.00.3 04.zip
References
PHP-Fusion Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Couple of minor fixes (PHP-Fusion)
- PHP-Fusion Homepage (PHP-Fusion)