[NT] Multiple Cross Site Scripting Vulnerabilities in FuseTalk
From: SecuriTeam (support_at_securiteam.com)
Date: 10/18/04
- Previous message: SecuriTeam: "[REVS] GDI+ JPEG Exploit Mutations Can Bypass Antivirus Tests"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 18 Oct 2004 15:03:41 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Multiple Cross Site Scripting Vulnerabilities in FuseTalk
------------------------------------------------------------------------
SUMMARY
<http://www.fusetalk.com/> FuseTalk is a web based discussion forum
system.
FuseTalk suffers from multiple cross site scripting vulnerabilities.
DETAILS
Vulnerable Systems:
* FuseTalk Enterprise Edition Version 2.0. Other versions might be also
affected.
In some forums (often older version) when viewing the profile of users, if
scripting code is passed into: tombstone.cfm?ProfileID the text is once
again unfiltered and the script with be executed.
Example:
http://example.com/forum/tombstone.cfm?ProfileID=