Vulnerabilities > CVE-2005-4516 - Cross-Site Scripting vulnerability in PHP-Fusion Members.PHP

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
php-fusion
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web script or HTML via (1) the sortby parameter in members.php and (2) IMG tags.

Exploit-Db

descriptionPHP-Fusion 6.0 Members.PHP Cross-Site Scripting Vulnerability. CVE-2005-4516. Webapps exploit for php platform
idEDB-ID:26872
last seen2016-02-03
modified2005-12-19
published2005-12-19
reporterkrasza
sourcehttps://www.exploit-db.com/download/26872/
titlePHP-Fusion 6.0 Members.PHP Cross-Site Scripting Vulnerability