CVE Vulnerabilities

CVE-2006-3555

Published: Jul 13, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer.

Affected Software

Name Vendor Start Version End Version
Php_fusion Php_fusion 6.00.3 (including) 6.00.3 (including)
Php_fusion Php_fusion 6.00.100 (including) 6.00.100 (including)
Php_fusion Php_fusion 6.00.101 (including) 6.00.101 (including)
Php_fusion Php_fusion 6.00.102 (including) 6.00.102 (including)
Php_fusion Php_fusion 6.00.103 (including) 6.00.103 (including)
Php_fusion Php_fusion 6.00.104 (including) 6.00.104 (including)
Php_fusion Php_fusion 6.0.105 (including) 6.0.105 (including)
Php_fusion Php_fusion 6.00.105 (including) 6.00.105 (including)
Php_fusion Php_fusion 6.00.106 (including) 6.00.106 (including)
Php_fusion Php_fusion 6.0.106 (including) 6.0.106 (including)
Php_fusion Php_fusion 6.00.107 (including) 6.00.107 (including)
Php_fusion Php_fusion 6.0.107 (including) 6.0.107 (including)
Php_fusion Php_fusion 6.00.108 (including) 6.00.108 (including)
Php_fusion Php_fusion 6.00.109 (including) 6.00.109 (including)
Php_fusion Php_fusion 6.00.110 (including) 6.00.110 (including)
Php_fusion Php_fusion 6.00.200 (including) 6.00.200 (including)
Php_fusion Php_fusion 6.00.204 (including) 6.00.204 (including)
Php_fusion Php_fusion 6.00.205 (including) 6.00.205 (including)
Php_fusion Php_fusion 6.00.206 (including) 6.00.206 (including)
Php_fusion Php_fusion 6.00.207 (including) 6.00.207 (including)
Php_fusion Php_fusion 6.00.300 (including) 6.00.300 (including)
Php_fusion Php_fusion 6.00.303 (including) 6.00.303 (including)
Php_fusion Php_fusion 6.00.304 (including) 6.00.304 (including)
Php_fusion Php_fusion 6.00.306 (including) 6.00.306 (including)
Php_fusion Php_fusion 6.00.307 (including) 6.00.307 (including)
Php_fusion Php_fusion 6.01.2 (including) 6.01.2 (including)

References