CVE-2007-3339
FuseTalk - Cross-Site Scripting via FTVAR_LINKP, FTVAR_URLP, and FTVAR_SCRIPTRUN Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2007-3339. PoCs published by Ivan Almuina.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in FuseTalk, where user-supplied input is not sufficiently sanitized. The example URL demonstrates how an attacker could inject malicious scripts via the 'FTVAR_SCRIPTRUN' parameter.
Description
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.
Exploits (3)
The provided text describes a cross-site scripting (XSS) vulnerability in FuseTalk, where user-supplied input is not sufficiently sanitized. The example URL demonstrates how an attacker could inject malicious scripts via the 'FTVAR_SCRIPTRUN' parameter.
The provided text describes a cross-site scripting (XSS) vulnerability in FuseTalk, where user-supplied input is not properly sanitized. It includes example URLs demonstrating how an attacker could exploit the vulnerability by injecting malicious scripts.
The provided code is a writeup describing a cross-site scripting (XSS) vulnerability in FuseTalk. It includes a proof-of-concept URL demonstrating how an attacker can inject malicious scripts via the 'FTVAR_SCRIPTRUN' parameter.