High severity8.8NVD Advisory· Published Jul 30, 2004· Updated Apr 16, 2026
CVE-2004-1703
CVE-2004-1703
Description
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
Affected products
1- cpe:2.3:a:fusionphp:fusion_news:3.6.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- securitytracker.com/idnvdBroken LinkExploitThird Party AdvisoryVDB EntryVendor Advisory
- www.securityfocus.com/bid/10836nvdBroken LinkExploitThird Party AdvisoryVDB EntryVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/16853nvdThird Party AdvisoryVDB Entry
- marc.infonvdMailing List
News mentions
0No linked articles in our index yet.