Description
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-5849 Vulnerability (CVE-2013-5849)
WordPress Plugin Client Dash Cross-Site Scripting (2.1.4)
WordPress Plugin Asgaros Forum Cross-Site Request Forgery (1.5.8)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2048)
WordPress Plugin Ultimate TinyMCE 'swfupload.swf' Cross-Site Scripting (3.5)