Lucene search

K
cveMitreCVE-2006-3555
HistoryJul 13, 2006 - 12:05 a.m.

CVE-2006-3555

2006-07-1300:05:00
mitre
web.nvd.nist.gov
22
php-fusion
xss
vulnerability
remote attackers
web script
html
nvd

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.004

Percentile

74.7%

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer.

Affected configurations

Nvd
Node
php_fusionphp_fusionMatch6.00.3
OR
php_fusionphp_fusionMatch6.00.100
OR
php_fusionphp_fusionMatch6.00.101
OR
php_fusionphp_fusionMatch6.00.102
OR
php_fusionphp_fusionMatch6.00.103
OR
php_fusionphp_fusionMatch6.00.104
OR
php_fusionphp_fusionMatch6.0.105
OR
php_fusionphp_fusionMatch6.00.105
OR
php_fusionphp_fusionMatch6.00.106
OR
php_fusionphp_fusionMatch6.0.106
OR
php_fusionphp_fusionMatch6.00.107
OR
php_fusionphp_fusionMatch6.0.107
OR
php_fusionphp_fusionMatch6.00.108
OR
php_fusionphp_fusionMatch6.00.109
OR
php_fusionphp_fusionMatch6.00.110
OR
php_fusionphp_fusionMatch6.00.200
OR
php_fusionphp_fusionMatch6.00.204
OR
php_fusionphp_fusionMatch6.00.205
OR
php_fusionphp_fusionMatch6.00.206
OR
php_fusionphp_fusionMatch6.00.207
OR
php_fusionphp_fusionMatch6.00.300
OR
php_fusionphp_fusionMatch6.00.303
OR
php_fusionphp_fusionMatch6.00.304
OR
php_fusionphp_fusionMatch6.00.306
OR
php_fusionphp_fusionMatch6.00.307
OR
php_fusionphp_fusionMatch6.01.2
VendorProductVersionCPE
php_fusionphp_fusion6.00.3cpe:2.3:a:php_fusion:php_fusion:6.00.3:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.100cpe:2.3:a:php_fusion:php_fusion:6.00.100:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.101cpe:2.3:a:php_fusion:php_fusion:6.00.101:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.102cpe:2.3:a:php_fusion:php_fusion:6.00.102:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.103cpe:2.3:a:php_fusion:php_fusion:6.00.103:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.104cpe:2.3:a:php_fusion:php_fusion:6.00.104:*:*:*:*:*:*:*
php_fusionphp_fusion6.0.105cpe:2.3:a:php_fusion:php_fusion:6.0.105:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.105cpe:2.3:a:php_fusion:php_fusion:6.00.105:*:*:*:*:*:*:*
php_fusionphp_fusion6.00.106cpe:2.3:a:php_fusion:php_fusion:6.00.106:*:*:*:*:*:*:*
php_fusionphp_fusion6.0.106cpe:2.3:a:php_fusion:php_fusion:6.0.106:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.004

Percentile

74.7%

Related for CVE-2006-3555