"evaluatorSolution":"Successful exploitation requires that register_globals is enabled.\r\nThis vulnerability is addressed in the following product release:\r\nPhorum, Phorum, 5.1.15",
"descriptions":[
{
"lang":"en",
"value":"Cross-site scripting (XSS) vulnerability in Phorum 5.1.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
},
{
"lang":"es",
"value":"Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Phorum 5.1.14 permite a atacantes remotos inyectar secuencias de comando web o HTML a trav\u00e9s de vectores no especificados."