6.8
CVSSv2

CVE-2005-3543

Published: 16/11/2005 Updated: 18/10/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in search.php in Phorum 5.0.0alpha up to and including 5.0.20, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the forum_ids parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phorum phorum 5.0.13

phorum phorum 5.0.13a

phorum phorum 5.0.19

phorum phorum 5.0.2_alpha

phorum phorum 5.0.7_beta

phorum phorum 5.0.7a_beta

phorum phorum 5.0.8_rc

phorum phorum 5.0.1_alpha

phorum phorum 5.0.10

phorum phorum 5.0.15

phorum phorum 5.0.16

phorum phorum 5.0.4_beta

phorum phorum 5.0.4a_beta

phorum phorum 5.0.11

phorum phorum 5.0.12

phorum phorum 5.0.17

phorum phorum 5.0.18

phorum phorum 5.0.5_beta

phorum phorum 5.0.6_beta

phorum phorum 5.0.0_alpha

phorum phorum 5.0.14

phorum phorum 5.0.14a

phorum phorum 5.0.20

phorum phorum 5.0.3_beta

phorum phorum 5.0.9