Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2004-1938

SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.9%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-1938
  • Phorum » Phorum » Version: 3.4.7
    cpe:2.3:a:phorum:phorum:3.4.7
  • Phorum » Phorum » Version: 3.4.8
    cpe:2.3:a:phorum:phorum:3.4.8


Contact Us

Shodan ® - All rights reserved