PT-2004-1249 · Phorum · Phorum

Calum Power

·

Publicado

2004-01-08

·

Atualizado

2017-07-11

·

CVE-2004-0034

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phorum versions 3.4.5 and earlier
Description The issue allows remote attackers to inject arbitrary HTML or web script. This is achieved through multiple vectors, including the phorum check xss function in common.php, the EditError variable in profile.php, and the Error variable in login.php.
Recommendations For Phorum versions 3.4.5 and earlier, consider disabling the phorum check xss function in common.php, restricting access to the EditError variable in profile.php, and limiting the use of the Error variable in login.php until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0034

Produtos afetados

Phorum