CVE-2011-4561: XSS
Published Nov 28, 2011
·Updated
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to admin/index.php. NOTE: some of these details are obtained from third party information.
Affected Software
1 affected component
Phorum Phorum=5.2.18
Event History
Nov 28, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4561?
CVE-2011-4561 has a moderate severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2011-4561?
To resolve CVE-2011-4561, upgrade Phorum to a version higher than 5.2.18 that includes a fix for this vulnerability.
3
What type of vulnerability is CVE-2011-4561?
CVE-2011-4561 is classified as a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2011-4561?
Users of Phorum version 5.2.18 are affected by CVE-2011-4561.
5
Can CVE-2011-4561 be exploited remotely?
Yes, CVE-2011-4561 can be exploited remotely by attackers through crafted requests to the affected application.