6.8
CVSSv2

CVE-2005-3543

Published: 16/11/2005 Updated: 18/10/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in search.php in Phorum 5.0.0alpha up to and including 5.0.20, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the forum_ids parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phorum phorum 5.0.15

phorum phorum 5.0.1 alpha

phorum phorum 5.0.13a

phorum phorum 5.0.2 alpha

phorum phorum 5.0.5 beta

phorum phorum 5.0.19

phorum phorum 5.0.7a beta

phorum phorum 5.0.17

phorum phorum 5.0.18

phorum phorum 5.0.4a beta

phorum phorum 5.0.12

phorum phorum 5.0.20

phorum phorum 5.0.0 alpha

phorum phorum 5.0.16

phorum phorum 5.0.10

phorum phorum 5.0.11

phorum phorum 5.0.14a

phorum phorum 5.0.9

phorum phorum 5.0.14

phorum phorum 5.0.7 beta

phorum phorum 5.0.6 beta

phorum phorum 5.0.3 beta

phorum phorum 5.0.4 beta

phorum phorum 5.0.13

phorum phorum 5.0.8 rc