CVE-2004-1822
Phorum 3.1-5.0.3 beta - Cross-Site Scripting via HTTP_REFERER or Target Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2004-1822. PoCs published by JeiAr.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Phorum versions 5.0.3 Beta and prior. The vulnerability is due to improper sanitization of user-supplied input in hidden variables 'f' and 'target' passed via HTTP_REFERER in multiple modules.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.
Exploits (3)
The provided text describes a cross-site scripting (XSS) vulnerability in Phorum versions 5.0.3 Beta and prior. The vulnerability is due to improper sanitization of user-supplied input in hidden variables 'f' and 'target' passed via HTTP_REFERER in multiple modules.
The provided text describes a cross-site scripting (XSS) vulnerability in Phorum versions 5.0.3 Beta and prior. The vulnerability is due to improper sanitization of user-supplied input in hidden variables 'f' and 'target' across multiple modules.
The provided text describes a cross-site scripting (XSS) vulnerability in Phorum versions 5.0.3 Beta and prior. The vulnerability is due to improper sanitization of user-supplied input in the 'f' and 'target' hidden variables, which are passed via HTTP_REFERER in multiple modules including 'login.php', 'register.php', and 'profile.php'.