CVE-2004-0034: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorumcheckxss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0034?
CVE-2004-0034 is classified as a medium severity vulnerability due to potential exploitation leading to cross-site scripting attacks.
How do I fix CVE-2004-0034?
To fix CVE-2004-0034, upgrade to Phorum version 3.4.6 or later where this vulnerability has been patched.
What types of attacks are associated with CVE-2004-0034?
CVE-2004-0034 is associated with cross-site scripting (XSS) attacks that can allow attackers to inject and execute arbitrary scripts in users' browsers.
Which versions of Phorum are affected by CVE-2004-0034?
CVE-2004-0034 affects Phorum versions 3.4.5 and earlier.
Can CVE-2004-0034 be exploited remotely?
Yes, CVE-2004-0034 can be exploited remotely by attackers to execute malicious scripts on the affected system.