CVE-2004-1703 Information

Description

Fusion News 3.6.1 allows remote attackers to add user accounts if the administrator is logged in via a comment that contains an img bbcode tag that calls index.php with the signup action which is executed when the administrator’s browser loads the page with the img tag.

Reference

http://marc.info/?l=bugtraq&m=109122824523226&w=2 http://securitytracker.com/id?1010829 http://www.securityfocus.com/bid/10836 https://exchange.xforce.ibmcloud.com/vulnerabilities/16853

Share on: