5.8
CVSSv2

CVE-2006-3555

Published: 13/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion prior to 6.01.3 allow remote malicious users to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer.

Vulnerable Product Search on Vulmon Subscribe to Product

php fusion php fusion 6.00.102

php fusion php fusion 6.00.103

php fusion php fusion 6.00.110

php fusion php fusion 6.00.200

php fusion php fusion 6.00.304

php fusion php fusion 6.00.306

php fusion php fusion 6.0.105

php fusion php fusion 6.00.104

php fusion php fusion 6.00.105

php fusion php fusion 6.00.204

php fusion php fusion 6.00.205

php fusion php fusion 6.00.307

php fusion php fusion 6.01.2

php fusion php fusion 6.0.106

php fusion php fusion 6.0.107

php fusion php fusion 6.00.106

php fusion php fusion 6.00.107

php fusion php fusion 6.00.206

php fusion php fusion 6.00.207

php fusion php fusion 6.00.100

php fusion php fusion 6.00.101

php fusion php fusion 6.00.108

php fusion php fusion 6.00.109

php fusion php fusion 6.00.3

php fusion php fusion 6.00.300

php fusion php fusion 6.00.303