3.5
CVE-2007-3559
- EPSS 0.87%
- Veröffentlicht 04.07.2007 16:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php-fusion ≫ Php-fusion Version6.01.9
Php-fusion ≫ Php-fusion Version6.01.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.87% | 0.54 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
http://osvdb.org/36342
http://secunia.com/advisories/25907
http://www.securityfocus.com/bid/24733
http://www.xssed.com/advisory/60/PHP-FUSION_FUSION_QUERY_Cross-Site_Scripting_Vulnerability/
https://exchange.xforce.ibmcloud.com/vulnerabilities/35225