Phorum 5.0.7 - Search Script Cross-Site Scripting



EKU-ID: 29745 CVE: CVE-2004-2242;OSVDB-38022 OSVDB-ID:
Author: vampz Published: 2004-07-28 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/10822/info

A cross-site scripting vulnerability is reported to affect Phorum. This issue affects the 'search.php' script. As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user.

This vulnerability was reported to affect Phorum 5.0.7 beta.

http://www.example.com/phorum5/search.php?12,search=vamp,page=1,match_type=ALL,
match_dates=00,match_forum=ALL ,body=,author=,subject= [ Evil Code Here ]