Author : Ph03n1X http://gombong.6te.net king_purba@yahoo.co.uk Software Description : Name : PHP Fusebox Vendor : http://sourceforge.net/projects/php-fusebox/ PoC : HTML injection in PHP Fusebox http://site.xxx/fusebox/index.php?fuseaction=
Vulnerable Code in file fbx_Fusebox3.0_PHP4.0.6.php : $FB_["rawFA"] = ($attributes["fuseaction"]); if(ListLen($FB_["rawFA"], ".") == 1 && substr($FB_["rawFA"], -1) == ".") { $Fusebox["fuseaction"] = "Fusebox.defaultFuseaction"; } Fix: $FB_["rawFA"] = htmlspecialchars($attributes["fuseaction"]); if(ListLen($FB_["rawFA"], ".") == 1 && substr($FB_["rawFA"], -1) == ".") { $Fusebox["fuseaction"] = "Fusebox.defaultFuseaction"; } Greetz : Zhainal, No-p****le (Bole disebut gak namanya om), All crew IndonesiaHack @ dalnet Nanang SW, nightlogin