Vulnerabilities > CVE-2004-2438 - Unspecified vulnerability in PHP Fusion PHP Fusion 4.01
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN php-fusion
nessus
Summary
Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | PHP_FUSION_SQL_INJECT.NASL |
description | A vulnerability exists in the version of PHP-Fusion installed on the remote host that may allow an authenticated attacker to inject arbitrary SQL code due to improper validation of user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15433 |
published | 2004-10-08 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15433 |
title | PHP-Fusion 4.01 Multiple Vulnerabilities |
code |
|
References
- http://secunia.com/advisories/12686/
- http://secunia.com/advisories/12686/
- http://www.osvdb.org/10439
- http://www.osvdb.org/10439
- http://www.securityfocus.com/bid/11296
- http://www.securityfocus.com/bid/11296
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17548