First published: Sun Mar 20 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phorum | =5.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0783 is classified as medium severity due to the potential for exploitation through cross-site scripting.
To fix CVE-2005-0783, upgrade Phorum to version 5.0.14a or later, which corrects the XSS vulnerability.
CVE-2005-0783 affects Phorum versions prior to 5.0.14a.
CVE-2005-0783 is a cross-site scripting (XSS) vulnerability allowing remote code injection.
Yes, CVE-2005-0783 can lead to data compromise by allowing attackers to execute malicious scripts in users' browsers.