Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2011-3392

Disclosure Date: September 08, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in control.php in the controlcenter in Phorum before 5.2.17 allows remote attackers to inject arbitrary web script or HTML via the real_name parameter.
0
Attacker Value
Unknown

CVE-2011-3382

Disclosure Date: September 08, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3381

Disclosure Date: September 08, 2011 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-1629

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.15 allows remote attackers to inject arbitrary web script or HTML via an invalid email address.
0
Attacker Value
Unknown

CVE-2009-0488

Disclosure Date: February 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1486

Disclosure Date: March 24, 2008 (last updated October 04, 2023)
SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands via the non-fulltext search.
0
Attacker Value
Unknown

CVE-2006-3611

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into a log file, which is then included by pm.php.
0
Attacker Value
Unknown

CVE-2005-3543

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.
0
Attacker Value
Unknown

CVE-2005-2836

Disclosure Date: September 07, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," which is not properly handled by control.php.
0
Attacker Value
Unknown

CVE-2005-0843

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.
0