Phorum login.PHP Cross Site Scripting Vulnerability
BID:7577
Info
Phorum login.PHP Cross Site Scripting Vulnerability
| Bugtraq ID: | 7577 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2003 12:00AM |
| Updated: | May 13 2003 12:00AM |
| Credit: | Discovery is credited to <[email protected]> |
| Vulnerable: |
Phorum Phorum 3.4.2 Phorum Phorum 3.4.1 Phorum Phorum 3.4 |
| Not Vulnerable: |
Phorum Phorum 3.4.3 |
Discussion
Phorum login.PHP Cross Site Scripting Vulnerability
A cross site scripting vulnerability has been discovered in Phorum 3.4.3. The problem occurs due to insufficient sanitization of user-supplied URI parameters to the login.php script. As a result, it may be possible to execute arbitrary script code within the browser of a target user who follows a maliciously constructed link.
A cross site scripting vulnerability has been discovered in Phorum 3.4.3. The problem occurs due to insufficient sanitization of user-supplied URI parameters to the login.php script. As a result, it may be possible to execute arbitrary script code within the browser of a target user who follows a maliciously constructed link.