PHP-Fusion 5.0 - BBCode IMG Tag Script Injection
Author: FireSt0rm
type: webapps
platform: php
port:
date_added: 2005-03-08
date_updated: 2013-05-04
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/12751/info
PHP-Fusion is reported prone to a script injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input prior to including it in dynamically generated content.
An attacker can supply ASCII equivalents of arbitrary HTML and script code through the BBCode IMG tag to trigger this issue and execute arbitrary script code in a user's browser.
PHP-Fusion 5.00 is reportedly affected by this issue.
[IMG]javascript:document.location='http://www.albinoblacksheep.com/flash/you.html'[/IMG]