Exploit Phorum 3.4 - Email Subject Line Script Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22451
Проверка EDB
  1. Пройдено
Автор
PETER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2003-04-02
Код:
source: https://www.securityfocus.com/bid/7262/info

It has been reported that it is possible to inject script code into the subject of a message in Phorum. This may be done by constructing a malicious subject line (or other fields) before sending an email to the target victim. 

"><script>alert("Vulnerable");</script>
 
Источник
www.exploit-db.com

Похожие темы