Page 3 of 22 results (0.004 seconds)
CVSS: 6.1EPSS: 0%CPEs: 42EXPL: 1
CVSS: 8.8EPSS: 0%CPEs: 6EXPL: 2

CVE-2005-2836
https://notcve.org/view.php?id=CVE-2005-2836
07 Sep 2005 — Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," which is not properly handled by control.php. • http://archives.neohapsis.com/archives/fulldisclosure/2005-09/0018.html •

CVE-2004-1518
https://notcve.org/view.php?id=CVE-2004-1518
31 Dec 2004 — SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028609.html •