Phorum kayıtları
phorum üreticisine ait 57 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
57 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2003-1487İstismar yok | Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify thephorum · phorum · CWE-20 | Kritik10,0 | — | %8,0 | 31 Ara 2003 |
41Planlayın | CVE-2002-0764Kavram kanıtı | Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php thaphorum · phorum | Yüksek7,5 | — | %38,3 | 12 Ağu 2002 |
33İzleyin | CVE-2007-2338Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauphorum · phorum | Yüksek7,5 | — | %8,7 | 27 Nis 2007 |
31İzleyin | CVE-2006-3053Kavram kanıtı | PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code viaphorum · phorum | Yüksek7,5 | — | %2,9 | 16 Haz 2006 |
31İzleyin | CVE-2006-6550Kavram kanıtı | PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code viaphorum · phorum | Yüksek7,5 | — | %2,2 | 14 Ara 2006 |
31İzleyin | CVE-2000-1233İstismar yok | SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the phorum · phorum | Yüksek7,5 | — | %2,1 | 31 Ara 2000 |
31İzleyin | CVE-2007-2339Kavram kanıtı | Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified rphorum · phorum | Yüksek7,5 | — | %1,9 | 27 Nis 2007 |
30İzleyin | CVE-2004-2240İstismar yok | Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query stringphorum · phorum | Yüksek7,5 | — | %1,6 | 31 Ara 2004 |
30İzleyin | CVE-2004-2243İstismar yok | Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter,phorum · phorum | Yüksek7,5 | — | %1,5 | 31 Ara 2004 |
30İzleyin | CVE-2003-1466İstismar yok | Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) regphorum · phorum | Yüksek7,5 | — | %1,5 | 31 Ara 2003 |
30İzleyin | CVE-2004-0035İstismar yok | SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hphorum · phorum | Yüksek7,5 | — | %1,2 | 20 Oca 2004 |
30İzleyin | CVE-2004-1938Kavram kanıtı | SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encodephorum · phorum | Yüksek7,5 | — | %1,2 | 19 Nis 2004 |
30İzleyin | CVE-2006-3249İstismar yok | SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the pagphorum · phorum | Yüksek7,5 | — | %1,2 | 27 Haz 2006 |
30İzleyin | CVE-2004-2110İstismar yok | SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_emphorum · phorum | Yüksek7,5 | — | %1,1 | 31 Ara 2004 |
28İzleyin | CVE-2007-2249Kavram kanıtı | include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_idphorum · phorum | Orta6,5 | — | %7,0 | 25 Nis 2007 |
28İzleyin | CVE-2003-0283Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a mphorum · phorum | Orta6,8 | — | %4,0 | 16 Haz 2003 |
27İzleyin | CVE-2005-3543İstismar yok | SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to phorum · phorum · CWE-89 | Orta6,8 | — | %1,4 | 16 Kas 2005 |
27İzleyin | CVE-2007-0769İstismar yok | Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML viaphorum · phorum | Orta6,8 | — | %1,2 | 5 Şub 2007 |
27İzleyin | CVE-2007-0767İstismar yok | Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML phorum · phorum | Orta6,8 | — | %1,2 | 5 Şub 2007 |
27İzleyin | CVE-2008-1486İstismar yok | SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commandsphorum · phorum · CWE-89 | Orta6,8 | — | %1,0 | 24 Mar 2008 |
27İzleyin | CVE-2011-3381İstismar yok | Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified phorum · phorum · CWE-352 | Orta6,8 | — | %0,6 | 8 Eyl 2011 |
24İzleyin | CVE-2011-3622İstismar yok | A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.phorum · phorum · CWE-79 | Orta6,1 | — | %0,7 | 22 Oca 2020 |
23İzleyin | CVE-2006-3611Kavram kanıtı | Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via dphorum · phorum | Orta5,5 | — | %2,2 | 18 Tem 2006 |
23İzleyin | CVE-2006-6968İstismar yok | Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow remote attackers tophorum · phorum | Orta5,8 | — | %1,1 | 5 Şub 2007 |
21İzleyin | CVE-2005-0843Kavram kanıtı | CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the bodyphorum · phorum | Orta5,0 | — | %3,9 | 2 May 2005 |
- CVE-2003-148742Planlayın
Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the
KritikCVSS 10,0İstismar yokEPSS %8phorum · phorum31 Ara 2003
- CVE-2002-076441Planlayın
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php tha
YüksekCVSS 7,5Kavram kanıtıEPSS %38phorum · phorum12 Ağu 2002
- CVE-2007-233833İzleyin
Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unau
YüksekCVSS 7,5Kavram kanıtıEPSS %9phorum · phorum27 Nis 2007
- CVE-2006-305331İzleyin
PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via
YüksekCVSS 7,5Kavram kanıtıEPSS %3phorum · phorum16 Haz 2006
- CVE-2006-655031İzleyin
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via
YüksekCVSS 7,5Kavram kanıtıEPSS %2phorum · phorum14 Ara 2006
- CVE-2000-123331İzleyin
SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the
YüksekCVSS 7,5İstismar yokEPSS %2phorum · phorum31 Ara 2000
- CVE-2007-233931İzleyin
Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified r
YüksekCVSS 7,5Kavram kanıtıEPSS %2phorum · phorum27 Nis 2007
- CVE-2004-224030İzleyin
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string
YüksekCVSS 7,5İstismar yokEPSS %2phorum · phorum31 Ara 2004
- CVE-2004-224330İzleyin
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter,
YüksekCVSS 7,5İstismar yokEPSS %2phorum · phorum31 Ara 2004
- CVE-2003-146630İzleyin
Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) reg
YüksekCVSS 7,5İstismar yokEPSS %1phorum · phorum31 Ara 2003
- CVE-2004-003530İzleyin
SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the h
YüksekCVSS 7,5İstismar yokEPSS %1phorum · phorum20 Oca 2004
- CVE-2004-193830İzleyin
SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encode
YüksekCVSS 7,5Kavram kanıtıEPSS %1phorum · phorum19 Nis 2004
- CVE-2006-324930İzleyin
SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the pag
YüksekCVSS 7,5İstismar yokEPSS %1phorum · phorum27 Haz 2006
- CVE-2004-211030İzleyin
SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_em
YüksekCVSS 7,5İstismar yokEPSS %1phorum · phorum31 Ara 2004
- CVE-2007-224928İzleyin
include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_id
OrtaCVSS 6,5Kavram kanıtıEPSS %7phorum · phorum25 Nis 2007
- CVE-2003-028328İzleyin
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a m
OrtaCVSS 6,8Kavram kanıtıEPSS %4phorum · phorum16 Haz 2003
- CVE-2005-354327İzleyin
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to
OrtaCVSS 6,8İstismar yokEPSS %1phorum · phorum16 Kas 2005
- CVE-2007-076927İzleyin
Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 6,8İstismar yokEPSS %1phorum · phorum5 Şub 2007
- CVE-2007-076727İzleyin
Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 6,8İstismar yokEPSS %1phorum · phorum5 Şub 2007
- CVE-2008-148627İzleyin
SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands
OrtaCVSS 6,8İstismar yokEPSS %1phorum · phorum24 Mar 2008
- CVE-2011-338127İzleyin
Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified
OrtaCVSS 6,8İstismar yokEPSS %1phorum · phorum8 Eyl 2011
- CVE-2011-362224İzleyin
A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.
OrtaCVSS 6,1İstismar yokEPSS %1phorum · phorum22 Oca 2020
- CVE-2006-361123İzleyin
Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via d
OrtaCVSS 5,5Kavram kanıtıEPSS %2phorum · phorum18 Tem 2006
- CVE-2006-696823İzleyin
Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow remote attackers to
OrtaCVSS 5,8İstismar yokEPSS %1phorum · phorum5 Şub 2007
- CVE-2005-084321İzleyin
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body
OrtaCVSS 5,0Kavram kanıtıEPSS %4phorum · phorum2 May 2005