Vulnerabilities (CVE)

Filtered by vendor Lukas Waldauf Subscribe
Filtered by product Phpfreeforum
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6437 1 Lukas Waldauf 1 Phpfreeforum 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.