Vulnerabilities > CVE-2005-2783 - Unspecified vulnerability in PHP Fusion PHP Fusion
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN php-fusion
nessus
Summary
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | PHP_FUSION_BBCODE_URL_XSS.NASL |
description | According to its version number, the remote host is running a version of PHP-Fusion that reportedly does not sufficiently sanitize input passed in nested |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19597 |
published | 2005-09-08 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19597 |
title | PHP-Fusion < 6.00.108 BBCode Nested URL Tag XSS |
code |
|
References
- http://marc.info/?l=bugtraq&m=112533836103267&w=2
- http://marc.info/?l=bugtraq&m=112533836103267&w=2
- http://secunia.com/advisories/16632/
- http://secunia.com/advisories/16632/
- http://www.securityfocus.com/bid/14688
- http://www.securityfocus.com/bid/14688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22056
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22056