Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.
References
Configurations
History
20 Nov 2024, 23:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=105251043821533&w=2 - | |
References | () http://marc.info/?l=bugtraq&m=105251421925394&w=2 - | |
References | () http://www.securityfocus.com/bid/7545 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/11974 - |
Information
Published : 2003-06-16 04:00
Updated : 2024-11-20 23:44
NVD link : CVE-2003-0283
Mitre link : CVE-2003-0283
CVE.ORG link : CVE-2003-0283
JSON object : View
Products Affected
phorum
- phorum
CWE