PT-2004-1249 · Phorum · Phorum

Calum Power

·

Published

2004-01-08

·

Updated

2017-07-11

·

CVE-2004-0034

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phorum versions 3.4.5 and earlier
Description The issue allows remote attackers to inject arbitrary HTML or web script. This is achieved through multiple vectors, including the phorum check xss function in common.php, the EditError variable in profile.php, and the Error variable in login.php.
Recommendations For Phorum versions 3.4.5 and earlier, consider disabling the phorum check xss function in common.php, restricting access to the EditError variable in profile.php, and limiting the use of the Error variable in login.php until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0034

Affected Products

Phorum