CVE-2012-4234 Information

Description

Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-08/0189.html http://packetstormsecurity.org/files/116057/Phorum-5.2.18-Cross-Site-Scripting.html http://secunia.com/advisories/50445 http://www.phorum.org/phorum5/read.php?64151943 http://www.securityfocus.com/bid/55275 https://exchange.xforce.ibmcloud.com/vulnerabilities/78124 https://www.htbridge.com/advisory/HTB23109

Share on: