5.6 Medium
AI Score
Confidence
High
0.006 Low
EPSS
Percentile
79.3%
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.
forum.fuzzylime.co.uk/st/content/download/
osvdb.org/36406
securityreason.com/securityalert/2815
www.securityfocus.com/archive/1/471649/100/0/threaded
www.securityfocus.com/bid/24522
www.secvsn.com/content/Advisories/sr-180607-fuzzy.html
exchange.xforce.ibmcloud.com/vulnerabilities/35137