CVE-2011-3392: XSS
Cross-site scripting (XSS) vulnerability in control.php in the controlcenter in Phorum before 5.2.17 allows remote attackers to inject arbitrary web script or HTML via the realname parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3392?
CVE-2011-3392 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2011-3392?
To fix CVE-2011-3392, you should upgrade Phorum to version 5.2.17 or later, where the vulnerability is addressed.
What software versions are affected by CVE-2011-3392?
CVE-2011-3392 affects multiple versions of Phorum prior to 5.2.17, including versions 5.2.10-rc1, 5.0.1_alpha, and earlier.
What types of attacks are possible due to CVE-2011-3392?
Due to CVE-2011-3392, attackers can inject arbitrary web scripts or HTML into the application, potentially compromising user data and security.
Does CVE-2011-3392 require user interaction to exploit?
CVE-2011-3392 does not require user interaction to exploit, making it a significant security risk.