Vulnerabilities
Vulnerable Software
Phorum:  >> Phorum  >> 5.0.10  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," which is not properly handled by control.php.
CVSS Score
4.3
EPSS Score
0.004
Published
2005-09-07
SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.
CVSS Score
4.6
EPSS Score
0.006
Published
2004-12-31


Contact Us

Shodan ® - All rights reserved