Перейти к содержимому
Noroxi

Записи Phorum

57 опубликованных записей вендора phorum.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
13
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

57 записей
  • CVE-2003-1487
    42В плане

    Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the

    КритическаяCVSS 10,0Эксплойта нетEPSS 8 %

    phorum · phorum31 дек. 2003 г.

  • CVE-2002-0764
    41В плане

    Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php tha

    ВысокаяCVSS 7,5Proof of conceptEPSS 38 %

    phorum · phorum12 авг. 2002 г.

  • CVE-2007-2338
    33Наблюдать

    Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unau

    ВысокаяCVSS 7,5Proof of conceptEPSS 9 %

    phorum · phorum27 апр. 2007 г.

  • CVE-2006-3053
    31Наблюдать

    PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    phorum · phorum16 июн. 2006 г.

  • CVE-2006-6550
    31Наблюдать

    PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    phorum · phorum14 дек. 2006 г.

  • CVE-2000-1233
    31Наблюдать

    SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    phorum · phorum31 дек. 2000 г.

  • CVE-2007-2339
    31Наблюдать

    Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified r

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    phorum · phorum27 апр. 2007 г.

  • CVE-2004-2240
    30Наблюдать

    Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    phorum · phorum31 дек. 2004 г.

  • CVE-2004-2243
    30Наблюдать

    Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter,

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    phorum · phorum31 дек. 2004 г.

  • CVE-2003-1466
    30Наблюдать

    Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) reg

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    phorum · phorum31 дек. 2003 г.

  • CVE-2004-0035
    30Наблюдать

    SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the h

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    phorum · phorum20 янв. 2004 г.

  • CVE-2004-1938
    30Наблюдать

    SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encode

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    phorum · phorum19 апр. 2004 г.

  • CVE-2006-3249
    30Наблюдать

    SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the pag

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    phorum · phorum27 июн. 2006 г.

  • CVE-2004-2110
    30Наблюдать

    SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_em

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    phorum · phorum31 дек. 2004 г.

  • CVE-2007-2249
    28Наблюдать

    include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_id

    СредняяCVSS 6,5Proof of conceptEPSS 7 %

    phorum · phorum25 апр. 2007 г.

  • CVE-2003-0283
    28Наблюдать

    Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a m

    СредняяCVSS 6,8Proof of conceptEPSS 4 %

    phorum · phorum16 июн. 2003 г.

  • CVE-2005-3543
    27Наблюдать

    SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    phorum · phorum16 нояб. 2005 г.

  • CVE-2007-0769
    27Наблюдать

    Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    phorum · phorum5 февр. 2007 г.

  • CVE-2007-0767
    27Наблюдать

    Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    phorum · phorum5 февр. 2007 г.

  • CVE-2008-1486
    27Наблюдать

    SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    phorum · phorum24 мар. 2008 г.

  • CVE-2011-3381
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    phorum · phorum8 сент. 2011 г.

  • CVE-2011-3622
    24Наблюдать

    A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    phorum · phorum22 янв. 2020 г.

  • CVE-2006-3611
    23Наблюдать

    Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via d

    СредняяCVSS 5,5Proof of conceptEPSS 2 %

    phorum · phorum18 июл. 2006 г.

  • CVE-2006-6968
    23Наблюдать

    Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow remote attackers to

    СредняяCVSS 5,8Эксплойта нетEPSS 1 %

    phorum · phorum5 февр. 2007 г.

  • CVE-2005-0843
    21Наблюдать

    CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body

    СредняяCVSS 5,0Proof of conceptEPSS 4 %

    phorum · phorum2 мая 2005 г.