First published: Tue Dec 31 2002(Updated: )
Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phorum | =3.3.2a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2340 is considered to be of medium severity due to its potential for cross-site scripting attacks.
To mitigate CVE-2002-2340, upgrade Phorum to a version later than 3.3.2a that addresses this XSS vulnerability.
CVE-2002-2340 specifically affects Phorum version 3.3.2a.
CVE-2002-2340 can be exploited through the 't' parameter and the body of an email response.
Exploiting CVE-2002-2340 could allow an attacker to inject arbitrary web scripts or HTML, potentially compromising user interactions.