CVE-2008-6437

Lukas Waldauf Phpfreeforum < 1.0 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by tan_prathan · textwebappsphp
https://www.exploit-db.com/exploits/31821
exploitdb WRITEUP VERIFIED
by tan_prathan · textwebappsphp
https://www.exploit-db.com/exploits/31822

Scores

EPSS 0.0038
EPSS Percentile 59.1%

Classification

CWE
CWE-79
Status published

Affected Products (2)

lukas_waldauf/phpfreeforum < 1.0
n/a/n/a

Timeline

Published Mar 06, 2009
Tracked Since Feb 18, 2026