Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-4234. PoCs published by High-Tech Bridge.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Phorum by injecting a malicious script via the 'group' parameter in the control.php file. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.
Description
Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Phorum by injecting a malicious script via the 'group' parameter in the control.php file. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.