Phorum Multiple Module Cross-Site Scripting Vulnerability

No exploit is required.

The following proof of concept has been provided:
login.php?HTTP_REFERER=[XSS]
register.php?&HTTP_REFERER=[XSS]
profile.php?id=2&action=edit&target=[XSS]


 

Privacy Statement
Copyright 2010, SecurityFocus