CVE-2002-2340: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response.
Affected Software
1 affected component
Phorum Phorum=3.3.2a
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 29, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2340?
CVE-2002-2340 is considered to be of medium severity due to its potential for cross-site scripting attacks.
2
How can I fix CVE-2002-2340?
To mitigate CVE-2002-2340, upgrade Phorum to a version later than 3.3.2a that addresses this XSS vulnerability.
3
What software is affected by CVE-2002-2340?
CVE-2002-2340 specifically affects Phorum version 3.3.2a.
4
What types of input can be exploited in CVE-2002-2340?
CVE-2002-2340 can be exploited through the 't' parameter and the body of an email response.
5
What are the potential impacts of exploiting CVE-2002-2340?
Exploiting CVE-2002-2340 could allow an attacker to inject arbitrary web scripts or HTML, potentially compromising user interactions.