CVE Vulnerabilities

CVE-2006-0593

Published: Feb 08, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via the (1) shout_name field in shoutbox_panel.php and the (2) comments field in comments_include.php.

Affected Software

Name Vendor Start Version End Version
Php_fusion Php_fusion 6.00.105 6.00.105
Php_fusion Php_fusion 6.00.106 6.00.106
Php_fusion Php_fusion 6.00.103 6.00.103
Php_fusion Php_fusion 6.00.101 6.00.101
Php_fusion Php_fusion 6.00.107 6.00.107
Php_fusion Php_fusion 6.00.303 6.00.303
Php_fusion Php_fusion 6.00.104 6.00.104
Php_fusion Php_fusion 6.00.100 6.00.100
Php_fusion Php_fusion 6.00.108 6.00.108
Php_fusion Php_fusion 6.00.207 6.00.207
Php_fusion Php_fusion 6.00.200 6.00.200
Php_fusion Php_fusion 6.00.110 6.00.110
Php_fusion Php_fusion 6.00.102 6.00.102
Php_fusion Php_fusion 6.00.205 6.00.205
Php_fusion Php_fusion 6.00.109 6.00.109
Php_fusion Php_fusion 6.00.206 6.00.206
Php_fusion Php_fusion 6.00.204 6.00.204
Php_fusion Php_fusion 6.00.300 6.00.300

References