10
CVSSv2

CVE-2003-1487

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple "command injection" vulnerabilities in Phorum 3.4 up to and including 3.4.2 allow remote malicious users to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.

Vulnerable Product Search on Vulmon Subscribe to Product

phorum phorum 3.4

phorum phorum 3.4.1

phorum phorum 3.4.2