VID |
210063 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The FuseTalk software is vulnerable to multiple cross-site scripting vulnerabilities in the autherror.cfm script. FuseTalk is a discussion forum implemented in ColdFusion. FuseTalk Basic, Standard, Enterprise, and ColdFusion could allow a remote attacker to inject arbitrary web script or HTML, caused by improper validation of user-supplied input passed to the comfinish.cfm or autherror.cfm script. A remote attacker could exploit this vulnerability using the FTVAR_SCRIPTRUN, FTVAR_LINKP, or FTVAR_URLP parameter to inject arbitrary HTML or script code into a user's browser to be executed within the security context of an affected Web site.
* References: http://archives.neohapsis.com/archives/bugtraq/2007-06/0257.html http://archives.neohapsis.com/archives/bugtraq/2007-06/0258.html http://secunia.com/advisories/25707
* Platforms Affected: FuseTalk Inc, FuseTalk 2.0 Any operating system Any version |
Recommendation |
Upgrade to the latest version of FuseTalk (after 6/19/2007 or later), avilable from the FuseTalk Web site at http://www.fusetalk.com/ |
Related URL |
CVE-2007-3339 (CVE) |
Related URL |
24563,24564 (SecurityFocus) |
Related URL |
34955 (ISS) |
|