Записи Phorum
57 опубликованных записей вендора phorum.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
57 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2003-1487Эксплойта нет | Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify thephorum · phorum · CWE-20 | Критическая10,0 | — | 8,0 % | 31 дек. 2003 г. |
41В плане | CVE-2002-0764Proof of concept | Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php thaphorum · phorum | Высокая7,5 | — | 38,3 % | 12 авг. 2002 г. |
33Наблюдать | CVE-2007-2338Proof of concept | Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauphorum · phorum | Высокая7,5 | — | 8,7 % | 27 апр. 2007 г. |
31Наблюдать | CVE-2006-3053Proof of concept | PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code viaphorum · phorum | Высокая7,5 | — | 2,9 % | 16 июн. 2006 г. |
31Наблюдать | CVE-2006-6550Proof of concept | PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code viaphorum · phorum | Высокая7,5 | — | 2,2 % | 14 дек. 2006 г. |
31Наблюдать | CVE-2000-1233Эксплойта нет | SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the phorum · phorum | Высокая7,5 | — | 2,1 % | 31 дек. 2000 г. |
31Наблюдать | CVE-2007-2339Proof of concept | Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified rphorum · phorum | Высокая7,5 | — | 1,9 % | 27 апр. 2007 г. |
30Наблюдать | CVE-2004-2240Эксплойта нет | Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query stringphorum · phorum | Высокая7,5 | — | 1,6 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2004-2243Эксплойта нет | Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter,phorum · phorum | Высокая7,5 | — | 1,5 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2003-1466Эксплойта нет | Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) regphorum · phorum | Высокая7,5 | — | 1,5 % | 31 дек. 2003 г. |
30Наблюдать | CVE-2004-0035Эксплойта нет | SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hphorum · phorum | Высокая7,5 | — | 1,2 % | 20 янв. 2004 г. |
30Наблюдать | CVE-2004-1938Proof of concept | SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encodephorum · phorum | Высокая7,5 | — | 1,2 % | 19 апр. 2004 г. |
30Наблюдать | CVE-2006-3249Эксплойта нет | SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the pagphorum · phorum | Высокая7,5 | — | 1,2 % | 27 июн. 2006 г. |
30Наблюдать | CVE-2004-2110Эксплойта нет | SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_emphorum · phorum | Высокая7,5 | — | 1,1 % | 31 дек. 2004 г. |
28Наблюдать | CVE-2007-2249Proof of concept | include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_idphorum · phorum | Средняя6,5 | — | 7,0 % | 25 апр. 2007 г. |
28Наблюдать | CVE-2003-0283Proof of concept | Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a mphorum · phorum | Средняя6,8 | — | 4,0 % | 16 июн. 2003 г. |
27Наблюдать | CVE-2005-3543Эксплойта нет | SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to phorum · phorum · CWE-89 | Средняя6,8 | — | 1,4 % | 16 нояб. 2005 г. |
27Наблюдать | CVE-2007-0769Эксплойта нет | Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML viaphorum · phorum | Средняя6,8 | — | 1,2 % | 5 февр. 2007 г. |
27Наблюдать | CVE-2007-0767Эксплойта нет | Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML phorum · phorum | Средняя6,8 | — | 1,2 % | 5 февр. 2007 г. |
27Наблюдать | CVE-2008-1486Эксплойта нет | SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commandsphorum · phorum · CWE-89 | Средняя6,8 | — | 1,0 % | 24 мар. 2008 г. |
27Наблюдать | CVE-2011-3381Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified phorum · phorum · CWE-352 | Средняя6,8 | — | 0,6 % | 8 сент. 2011 г. |
24Наблюдать | CVE-2011-3622Эксплойта нет | A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.phorum · phorum · CWE-79 | Средняя6,1 | — | 0,7 % | 22 янв. 2020 г. |
23Наблюдать | CVE-2006-3611Proof of concept | Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via dphorum · phorum | Средняя5,5 | — | 2,2 % | 18 июл. 2006 г. |
23Наблюдать | CVE-2006-6968Эксплойта нет | Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow remote attackers tophorum · phorum | Средняя5,8 | — | 1,1 % | 5 февр. 2007 г. |
21Наблюдать | CVE-2005-0843Proof of concept | CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the bodyphorum · phorum | Средняя5,0 | — | 3,9 % | 2 мая 2005 г. |
- CVE-2003-148742В плане
Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %phorum · phorum31 дек. 2003 г.
- CVE-2002-076441В плане
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php tha
ВысокаяCVSS 7,5Proof of conceptEPSS 38 %phorum · phorum12 авг. 2002 г.
- CVE-2007-233833Наблюдать
Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unau
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %phorum · phorum27 апр. 2007 г.
- CVE-2006-305331Наблюдать
PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phorum · phorum16 июн. 2006 г.
- CVE-2006-655031Наблюдать
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %phorum · phorum14 дек. 2006 г.
- CVE-2000-123331Наблюдать
SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phorum · phorum31 дек. 2000 г.
- CVE-2007-233931Наблюдать
Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified r
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %phorum · phorum27 апр. 2007 г.
- CVE-2004-224030Наблюдать
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phorum · phorum31 дек. 2004 г.
- CVE-2004-224330Наблюдать
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phorum · phorum31 дек. 2004 г.
- CVE-2003-146630Наблюдать
Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) reg
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phorum · phorum31 дек. 2003 г.
- CVE-2004-003530Наблюдать
SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the h
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phorum · phorum20 янв. 2004 г.
- CVE-2004-193830Наблюдать
SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encode
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phorum · phorum19 апр. 2004 г.
- CVE-2006-324930Наблюдать
SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the pag
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phorum · phorum27 июн. 2006 г.
- CVE-2004-211030Наблюдать
SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_em
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phorum · phorum31 дек. 2004 г.
- CVE-2007-224928Наблюдать
include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_id
СредняяCVSS 6,5Proof of conceptEPSS 7 %phorum · phorum25 апр. 2007 г.
- CVE-2003-028328Наблюдать
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a m
СредняяCVSS 6,8Proof of conceptEPSS 4 %phorum · phorum16 июн. 2003 г.
- CVE-2005-354327Наблюдать
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phorum · phorum16 нояб. 2005 г.
- CVE-2007-076927Наблюдать
Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phorum · phorum5 февр. 2007 г.
- CVE-2007-076727Наблюдать
Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phorum · phorum5 февр. 2007 г.
- CVE-2008-148627Наблюдать
SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phorum · phorum24 мар. 2008 г.
- CVE-2011-338127Наблюдать
Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phorum · phorum8 сент. 2011 г.
- CVE-2011-362224Наблюдать
A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %phorum · phorum22 янв. 2020 г.
- CVE-2006-361123Наблюдать
Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via d
СредняяCVSS 5,5Proof of conceptEPSS 2 %phorum · phorum18 июл. 2006 г.
- CVE-2006-696823Наблюдать
Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow remote attackers to
СредняяCVSS 5,8Эксплойта нетEPSS 1 %phorum · phorum5 февр. 2007 г.
- CVE-2005-084321Наблюдать
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body
СредняяCVSS 5,0Proof of conceptEPSS 4 %phorum · phorum2 мая 2005 г.