PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-1804 - Vulnerability Database

PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-1804

Medium
Reference: CVE-2013-1804
Title: PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php or remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (2) user_list or (3) user_types parameter to messages.php (4) message parameter to infusions/shoutbox_panel/shoutbox_admin.php (5) message parameter to administration/news.php (6) panel_list parameter to administration/panel_editor.php (7) HTTP User Agent string to administration/phpinfo.php (8) quot__BBCODE__quot parameter to administration/bbcodes.php errorMessage parameter to (9) article_cats.php (10) download_cats.php (11) news_cats.php or (12) weblink_cats.php in administration/ when error is 3 or (13) body or (14) body2 parameter to administration/articles.php.