Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phorum vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2011-3622
A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum prior to 5.2.18.
Phorum Phorum
NA
CVE-2007-2249
include/controlcenter/users.php in Phorum prior to 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.
Phorum Phorum
1 EDB exploit
NA
CVE-2006-3615
Multiple PHP remote file inclusion vulnerabilities in Phorum 5.1.14, when register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via unspecified vectors related to an uninitialized variable.
Phorum Phorum 5.1.14
NA
CVE-2006-3612
Cross-site scripting (XSS) vulnerability in Phorum 5.1.14 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Phorum Phorum 5.1.14
NA
CVE-2006-6550
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use
Phorum Phorum 3.2.11
1 EDB exploit
NA
CVE-2000-1230
Backdoor in auth.php3 in Phorum 3.0.7 allows remote malicious users to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".
Phorum Phorum 3.0.7
1 EDB exploit
NA
CVE-2000-1232
upgrade.php3 in Phorum 3.0.7 could allow remote malicious users to modify certain Phorum database tables via an unknown method.
Phorum Phorum 3.0.7
NA
CVE-2000-1233
SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote malicious users to execute arbitrary SQL queries via the sSQL parameter.
Phorum Phorum 3.0.7
NA
CVE-2011-4561
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information.
Phorum Phorum 5.2.18
1 EDB exploit
NA
CVE-2000-1228
Phorum 3.0.7 allows remote malicious users to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
Phorum Phorum 3.0.7
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »