First published: Wed Dec 31 2003(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | ||
Microsoft Windows | ||
Unix Unix | =any_version | |
Phorum Phorum | <=3.4.2 | |
Phorum Phorum | =3.4 | |
Phorum Phorum | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1467 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To remediate CVE-2003-1467, you should upgrade Phorum to version 3.4.3 or later.
CVE-2003-1467 affects login.php, register.php, post.php, and common.php in Phorum versions prior to 3.4.3.
Yes, CVE-2003-1467 can be exploited remotely by injecting arbitrary web scripts or HTML.
The impacts of CVE-2003-1467 include site defacement, cookie theft, and phishing attacks through cross-site scripting.