5
CVSSv2

CVE-2005-0345

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote malicious users to view protected forums via the thread_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php fusion php fusion 4.0

Exploits

source: wwwsecurityfocuscom/bid/12482/info PHP-Fusion is reportedly affected by an information disclosure vulnerability This issue is due to the application failing to properly sanitize user-supplied input It is reported that an attacker could leverage this vulnerability to view any thread of protected forums on an affected version of ...