7.5
CVSSv2

CVE-2007-2338

Published: 27/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum prior to 5.1.22 allows remote malicious users to perform unauthorized banlist deletions as an administrator via the delete parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phorum phorum

Exploits

source: wwwsecurityfocuscom/bid/23616/info Phorum is prone to multiple input-validation vulnerabilities, including an unauthorized-access issue, privilege-escalation issue, multiple SQL-injection issues, and cross-site scripting issues, because the application fails to sufficiently sanitize user-supplied input Exploiting these i ...