Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier via search.php

Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier via search.php

CVE-2004-2241 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.

Learn more about our Web App Pen Testing.