Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phorum phorum vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2003-0283
Cross-site scripting (XSS) vulnerability in Phorum prior to 3.4.3 allows remote malicious users to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.
Phorum Phorum
1 EDB exploit
NA
CVE-2007-2249
include/controlcenter/users.php in Phorum prior to 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.
Phorum Phorum
1 EDB exploit
NA
CVE-2007-0769
Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: the vendor disputes this vulnerability, stating that "The characters are escaped properly.
Phorum Phorum 5.1.18
NA
CVE-2008-4513
Cross-site scripting (XSS) vulnerability in BBcode API module in Phorum 5.2.8 allows remote malicious users to inject arbitrary web script or HTML via nested BBcode image tags.
Phorum Phorum 5.2.8
NA
CVE-2011-3768
Phorum 5.2.15a allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by css.php and certain other files.
Phorum Phorum 5.2.15a
NA
CVE-2006-6550
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use
Phorum Phorum 3.2.11
1 EDB exploit
NA
CVE-2005-0784
Multiple cross-site scripting (XSS) vulnerabilities in Phorum prior to 5.0.15 allow remote malicious users to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.
Phorum Phorum 5.0.14
NA
CVE-2004-2240
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and previous versions allow remote malicious users to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.
Phorum Phorum 5.0.11
NA
CVE-2004-2241
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and previous versions allows remote malicious users to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor'...
Phorum Phorum 5.0.11
NA
CVE-2004-2243
Phorum allows remote malicious users to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.
Phorum Phorum 4.3.7
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »