CVE-2004-2242: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.
Affected Software
1 affected component
Phorum Phorum=5.0.7_beta
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2242?
CVE-2004-2242 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2004-2242?
To fix CVE-2004-2242, update Phorum to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2004-2242?
CVE-2004-2242 affects Phorum versions 5.0.7 beta and earlier.
4
What type of vulnerability is CVE-2004-2242?
CVE-2004-2242 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary HTML or web scripts.
5
What could an attacker do with CVE-2004-2242?
An attacker exploiting CVE-2004-2242 could manipulate the subject parameter to execute malicious scripts in users' browsers.