PT-2004-1249 · Phorum · Phorum
Calum Power
·
Publicado
2004-01-08
·
Atualizado
2017-07-11
·
CVE-2004-0034
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Phorum versions 3.4.5 and earlier
Description
The issue allows remote attackers to inject arbitrary HTML or web script. This is achieved through multiple vectors, including the
phorum check xss function in common.php, the EditError variable in profile.php, and the Error variable in login.php.Recommendations
For Phorum versions 3.4.5 and earlier, consider disabling the
phorum check xss function in common.php, restricting access to the EditError variable in profile.php, and limiting the use of the Error variable in login.php until a fix is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phorum