source: https://www.securityfocus.com/bid/12751/info
PHP-Fusion is reported prone to a script injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input prior to including it in dynamically generated content.
An attacker can supply ASCII equivalents of arbitrary HTML and script code through the BBCode IMG tag to trigger this issue and execute arbitrary script code in a user's browser.
PHP-Fusion 5.00 is reportedly affected by this issue.
[IMG]javascript:document.location='http://www.albinoblacksheep.com/flash/you.html'[/IMG]