VYPR
Unrated severityNVD Advisory· Published Sep 8, 2011· Updated Apr 29, 2026

CVE-2011-3392

CVE-2011-3392

Description

Cross-site scripting (XSS) vulnerability in control.php in the controlcenter in Phorum before 5.2.17 allows remote attackers to inject arbitrary web script or HTML via the real_name parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in Phorum control panel allows attackers to inject arbitrary script via the real_name parameter.

Vulnerability

The control.php script in the controlcenter of Phorum versions before 5.2.17 contains a cross-site scripting (XSS) vulnerability. The real_name parameter is not properly sanitized before being output, allowing injection of arbitrary web script or HTML. [1]

Exploitation

An attacker can exploit this by crafting a malicious URL with a real_name parameter containing JavaScript code. No authentication is required if the attacker can trick a logged-in administrator into clicking the link, as the controlcenter is typically accessed by administrators. The attacker does not need any special network position beyond being able to deliver the link to the victim.

Impact

Successful exploitation allows the attacker to execute arbitrary script in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information. The impact is limited to the privileges of the victim user, typically an administrator.

Mitigation

The vulnerability is fixed in Phorum version 5.2.17, released on an unknown date but before the CVE publication date of 2011-09-08. Users should upgrade to 5.2.17 or later. No workarounds are mentioned in the reference. [1]

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

85
  • Phorum/Phorum85 versions
    cpe:2.3:a:phorum:phorum:*:*:*:*:*:*:*:*+ 84 more
    • cpe:2.3:a:phorum:phorum:*:*:*:*:*:*:*:*range: <=5.2.16
    • cpe:2.3:a:phorum:phorum:3.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.1.1a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.1.1_pre:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.1.1_rc2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.3a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.3b:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.3.1a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.3.2a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.3.2b3:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:3.4.8a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:4.3.7:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.0_alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.13a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.14a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.15a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.17a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.18:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.19:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.1_alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.20:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.2_alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.3_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.4a_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.4_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.5_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.6_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.7a_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.7_beta:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.8_rc:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.20:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.21:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.1.25:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.10:rc1:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.12:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.12a:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.13:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.14:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.15:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.2:beta:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.3:rc1:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.4:rc2:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:phorum:phorum:5.2.9:*:*:*:*:*:*:*
    • (no CPE)range: <5.2.17

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.