Page 11 of 60 results (0.002 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response. • http://marc.info/?l=vuln-dev&m=102121925428844&w=2 http://www.ifrance.com/kitetoua/tuto/5holes5.txt http://www.phorum.org/changelog.txt http://www.securityfocus.com/bid/4739 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 81%CPEs: 1EXPL: 2

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands. • https://www.exploit-db.com/exploits/21459 http://archives.neohapsis.com/archives/bugtraq/2002-05/0147.html http://archives.neohapsis.com/archives/bugtraq/2002-05/0153.html http://www.iss.net/security_center/static/9107.php http://www.phorum.org http://www.securityfocus.com/bid/4763 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication. • http://marc.info/?l=bugtraq&m=101508207206900&w=2 http://www.iss.net/security_center/static/8344.php http://www.securityfocus.com/bid/4226 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 1

upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method. • http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html http://hispahack.ccc.de/mi020.html http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm •

CVSS: 5.0EPSS: 2%CPEs: 1EXPL: 3

violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters. • https://www.exploit-db.com/exploits/20587 http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html http://hispahack.ccc.de/mi020.html http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm http://www.securityfocus.com/bid/2272 •