First published: Fri Mar 10 2006(Updated: )
Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phorum | =0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1151 has a moderate severity level due to its potential for cross-site scripting attacks.
To fix CVE-2006-1151, you should sanitize and validate the input for the 'go' parameter in index.php.
CVE-2006-1151 can allow remote attackers to execute arbitrary web scripts or HTML in the user's browser.
CVE-2006-1151 affects M-Phorum version 0.2.
Any remote attacker can exploit CVE-2006-1151 if they can send a crafted request to index.php with the vulnerable 'go' parameter.