Phorum Email Subject Line Script Injection Vulnerability
BID:7262
Info
Phorum Email Subject Line Script Injection Vulnerability
| Bugtraq ID: | 7262 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2003 12:00AM |
| Updated: | Apr 02 2003 12:00AM |
| Credit: | Discovery credited to Peter "Stöckli" <[email protected]>. |
| Vulnerable: |
Phorum Phorum 3.4.1 Phorum Phorum 3.4 |
| Not Vulnerable: |
Phorum Phorum 3.4.2 |
Discussion
Phorum Email Subject Line Script Injection Vulnerability
It has been reported that it is possible to inject script code into the subject of a message in Phorum. This may be done by constructing a malicious subject line (or other fields) before sending an email to the target victim.
It has been reported that it is possible to inject script code into the subject of a message in Phorum. This may be done by constructing a malicious subject line (or other fields) before sending an email to the target victim.
References
Phorum Email Subject Line Script Injection Vulnerability
References:
References:
- Phorum 3.4 XSS Exploit (Phorum)
- Phorum 3.4 Cross Site Scripting (Peter "Stöckli"
)