CVE-2003-1467: XSS
Published Dec 31, 2003
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Affected Software
12 affected components
Linux Linux kernel
Microsoft All Windows
Unix Unix=any_version
Phorum Phorum<=3.4.2
Phorum Phorum=3.4
Phorum Phorum=3.4.1
All of the following
Any of the following
Linux Linux kernel
Microsoft All Windows
Unix Unix=any_version
Any of the following
Phorum Phorum<=3.4.2
Phorum Phorum=3.4
Phorum Phorum=3.4.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 25, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1467?
CVE-2003-1467 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2003-1467?
To remediate CVE-2003-1467, you should upgrade Phorum to version 3.4.3 or later.
3
What components of Phorum are affected by CVE-2003-1467?
CVE-2003-1467 affects login.php, register.php, post.php, and common.php in Phorum versions prior to 3.4.3.
4
Can CVE-2003-1467 be exploited remotely?
Yes, CVE-2003-1467 can be exploited remotely by injecting arbitrary web scripts or HTML.
5
What are the potential impacts of CVE-2003-1467?
The impacts of CVE-2003-1467 include site defacement, cookie theft, and phishing attacks through cross-site scripting.