First published: Fri Jul 30 2004(Updated: )
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Fusion | =3.6.1 | |
PHP-Fusion | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1703 is considered a high severity vulnerability due to its potential for unauthorized account creation.
To fix CVE-2004-1703, ensure that you upgrade Fusion News to the latest version that addresses this vulnerability.
Users of Fusion News versions 3.6.1 and 3.3 are affected by CVE-2004-1703.
Attackers can add user accounts to the Fusion News platform if the administrator is logged in at the time.
The main vector of attack for CVE-2004-1703 is through a comment containing an img bbcode tag that triggers an account signup action.