Synopsis
The remote host is vulnerable to an HTML injection attack.
Description
The remote host is running a version of PHP-Fusion which is vulnerable to a script injection flaw. The 'fusion_core.php' script is reportedly vulnerable to an attack where an attacker can inject HTML and script code through the 'BBCode IMG' tag. An attacker exploiting this flaw would create a malicious URI link and then convince an unsuspecting user to click on the link. A successful attack would yield potentially confidential data (cookies, credentials) as well as potentially execute malicious code within the context of the vulnerable server.
Solution
Upgrade to version 5.01 or higher.
Plugin Details
Nessus ID: 17302
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Temporal Vector: CVSS:3.0/E:H/RL:O/RC:X
Vulnerability Information
CPE: cpe:/a:php_fusion:php_fusion