VulnerabilityModified
CVE-2008-6437
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to…
MEDIUM 4.3EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- lukas waldauf/phpfreeforum
- Source
- cve@mitre.org
References
- http://osvdb.org/45607
- http://osvdb.org/45608
- http://secunia.com/advisories/30372Vendor Advisory
- http://www.securityfocus.com/archive/1/492445/100/0/threaded
- http://www.securityfocus.com/bid/29337Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42586
- http://osvdb.org/45607
- http://osvdb.org/45608
- http://secunia.com/advisories/30372Vendor Advisory
- http://www.securityfocus.com/archive/1/492445/100/0/threaded
- http://www.securityfocus.com/bid/29337Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42586
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.