Vulnerabilities > CVE-2004-2241 - Cross-Site Scripting and SQL Injection vulnerability in Phorum 5.0.11
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
phorum
Summary
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |