The pod.board 'forum_details.php' script does not sufficiently sanitize data supplied via URI parameters and input fields, making it prone to HMTL injection attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code. Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.
The pod.board 'forum_details.php' script does not sufficiently sanitize data supplied via URI parameters and input fields, making it prone to HMTL injection attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code. Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.