CVE-2006-3555

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php_fusion:php_fusion:6.00.3:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.100:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.101:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.102:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.103:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.104:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.0.105:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.105:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.106:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.0.106:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.107:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.0.107:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.108:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.109:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.110:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.200:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.204:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.205:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.206:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.207:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.300:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.303:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.304:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.306:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.307:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.01.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:13

Type Values Removed Values Added
References () http://php-fusion.co.uk/news.php - () http://php-fusion.co.uk/news.php -
References () http://secunia.com/advisories/20904 - Patch, Vendor Advisory () http://secunia.com/advisories/20904 - Patch, Vendor Advisory
References () http://securityreason.com/securityalert/1224 - () http://securityreason.com/securityalert/1224 -
References () http://www.securityfocus.com/archive/1/438938/100/0/threaded - () http://www.securityfocus.com/archive/1/438938/100/0/threaded -
References () http://www.securityfocus.com/bid/18787 - Patch () http://www.securityfocus.com/bid/18787 - Patch
References () http://www.vupen.com/english/advisories/2006/2655 - () http://www.vupen.com/english/advisories/2006/2655 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27537 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27537 -

Information

Published : 2006-07-13 00:05

Updated : 2024-11-21 00:13


NVD link : CVE-2006-3555

Mitre link : CVE-2006-3555

CVE.ORG link : CVE-2006-3555


JSON object : View

Products Affected

php_fusion

  • php_fusion