PT-2004-1249 · Phorum · Phorum
Calum Power
·
Published
2004-01-08
·
Updated
2017-07-11
·
CVE-2004-0034
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Phorum versions 3.4.5 and earlier
Description
The issue allows remote attackers to inject arbitrary HTML or web script. This is achieved through multiple vectors, including the
phorum check xss function in common.php, the EditError variable in profile.php, and the Error variable in login.php.Recommendations
For Phorum versions 3.4.5 and earlier, consider disabling the
phorum check xss function in common.php, restricting access to the EditError variable in profile.php, and limiting the use of the Error variable in login.php until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phorum