Description
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
Remediation
References
Related Vulnerabilities
SugarCRM Missing Authorization Vulnerability (CVE-2020-7472)
WordPress Plugin Better Click To Tweet Unspecified Vulnerability (5.1)
Drupal Improper Input Validation Vulnerability (CVE-2019-6339)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.36)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9041)