===================================================================== ========================== DarkBicho ================================ PROGRAM: fusion news HOMEPAGE: http://www.fusionphp.net/ version: 3.6.1 Bug: Cross Site Scripting Date: 22/04/2004 Author: DarkBicho web: http://www.darkbicho.tk Email: darkbicho@peru.com ===================================================================== =============== 1) Introduction =============== fusion news is sofware free in php, This product is vulnerable to the Cross-Site Scripting vulnerability that would allow attackers to inject HTML and script codes into the pages and execute it on the client's browser as if it were provided by the site. =============== 2) Exploit =============== The XSS hole is in fullnews.php http://site vulnerable/fullnews.php?id= =============== 2) SOLUTION =============== the vendor was notified visits web site for patch ===================================================================== DARKBICHO Menbers: SWP www.swp-zone.org www.darkbicho.tk Made In Peru _________________________________________________________________ MSN Amor: busca tu ½ naranja http://latam.msn.com/amor/