CVE-2004-2241: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.
Affected Software
1 affected component
Phorum Phorum=5.0.11
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2241?
The severity of CVE-2004-2241 is considered moderate due to the potential impact of cross-site scripting attacks.
2
How do I fix CVE-2004-2241?
To fix CVE-2004-2241, upgrade Phorum to version 5.0.12 or later where the vulnerability has been patched.
3
Which versions of Phorum are affected by CVE-2004-2241?
CVE-2004-2241 affects Phorum versions 5.0.11 and earlier.
4
What type of vulnerability is CVE-2004-2241?
CVE-2004-2241 is a cross-site scripting (XSS) vulnerability.
5
How can attackers exploit CVE-2004-2241?
Attackers can exploit CVE-2004-2241 by injecting arbitrary HTML or web script through the search.php interface.