CVE-2003-0283: XSS
Published May 14, 2003
·Updated
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.
Affected Software
1 affected component
Phorum Phorum<=3.4.3
Event History
May 14, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 16, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0283?
CVE-2003-0283 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2003-0283?
To fix CVE-2003-0283, upgrade Phorum to version 3.4.4 or later.
3
What is the impact of CVE-2003-0283?
CVE-2003-0283 allows remote attackers to inject arbitrary web scripts and HTML into the application.
4
What versions of Phorum are affected by CVE-2003-0283?
Phorum versions prior to 3.4.3 are affected by CVE-2003-0283.
5
How can I mitigate CVE-2003-0283 if I can't upgrade Phorum?
If upgrading is not possible, implementing input validation and sanitization may help mitigate the effects of CVE-2003-0283.