CVE-2004-1703

Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fusionphp:fusion_news:3.3:*:*:*:*:*:*:*
cpe:2.3:a:fusionphp:fusion_news:3.6.1:*:*:*:*:*:*:*

Information

Published : 2004-07-30 04:00

Updated : 2017-07-11 01:31


NVD link : CVE-2004-1703

Mitre link : CVE-2004-1703


JSON object : View

Products Affected

fusionphp

  • fusion_news