Exploit Phorum 3.4.x - 'Message Form' HTML Injection

Exploiter

Хакер
34,599
0
18 Дек 2022
EDB-ID
22579
Проверка EDB
  1. Пройдено
Автор
WICIU
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2003-0283
Дата публикации
2003-05-09
Код:
source: https://www.securityfocus.com/bid/7545/info

An HTML injection issue has been reported which may lead to unauthorized code execution.

It has been reported that it is possible to inject HTML or script code into the subject and other fields of a message in Phorum. This may be done by including code in message fields before sending a message to the target victim.

<<b>script>alert(document.cookie);<<b>/script>
 
Источник
www.exploit-db.com

Похожие темы