Description
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2013-3760 Vulnerability (CVE-2013-3760)
Oracle Database Server CVE-2015-0371 Vulnerability (CVE-2015-0371)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Multiple Vulnerabilities (3.3.0)
WordPress Plugin Better Search Cross-Site Request Forgery (2.5.2)