CVE-2011-4561
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information.
Date published : 2011-11-28
http://www.securityfocus.com/bid/49920
http://www.securityfocus.com/archive/1/519991/100/0/threaded