Unrated severityNVD Advisory· Published Apr 25, 2007· Updated Apr 23, 2026
CVE-2007-2248
CVE-2007-2248
Description
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.phorum.org/story.phpnvdPatch
- secunia.com/advisories/24932nvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/23616nvdExploitPatch
- www.securitytracker.com/idnvdExploitPatchVendor Advisory
- www.waraxe.us/advisory-49.htmlnvdExploitPatchVendor Advisory
- osvdb.org/35057nvd
- osvdb.org/35058nvd
- securityreason.com/securityalert/2617nvd
- www.securityfocus.com/archive/1/466286/100/0/threadednvd
News mentions
0No linked articles in our index yet.