← Back

CVE-2006-3555

nvd nist
Published: Jul 13, 2006Modified: Apr 16, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) avatar or (2) forum image attachment that has a .gif or .jpg extension, and begins with a GIF header followed by JavaScript code, which is executed by Internet Explorer.

Affected (26)

1 product
Php Fusion
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Php Fusion
Version 6.0.105
Version 6.0.106
Version 6.0.107
Version 6.00.100
Version 6.00.101
Version 6.00.102
Version 6.00.103
Version 6.00.104
Version 6.00.105
Version 6.00.106
Version 6.00.107
Version 6.00.108
Version 6.00.109
Version 6.00.110
Version 6.00.200
Version 6.00.204
Version 6.00.205
Version 6.00.206
Version 6.00.207
Version 6.00.300
Version 6.00.303
Version 6.00.304
Version 6.00.306
Version 6.00.307
Version 6.00.3
Version 6.01.2

References (14)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.