Description
|
|
Two vulnerabilities were identified in PHP-Fusion, which may be exploited by remote attackers to execute arbitrary scripting code. These flaws are due to input validation errors in the "includes/comments_include.php" and "infusions/shoutbox_panel/shoutbox_panel.php" scripts that fail to properly validate the "comment_name" and "shout_name" variables, which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser in the security context of an affected Web site.
|