Description
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
Remediation
References
Related Vulnerabilities
WordPress Plugin Form Builder-Create Responsive Contact Forms Cross-Site Scripting (1.9.8.3)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.21)
Opencart Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-28838)
WordPress Plugin Kama Click Counter SQL Injection (3.4.9)
OpenSSL Use of Insufficiently Random Values Vulnerability (CVE-2019-1549)