CVE-2004-0035
https://notcve.org/view.php?id=CVE-2004-0035
SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter. Vulnerabilidad de inyección de SQL en register.php de Phorum 3.4.5 y anteriores permite a atacantes remotos ejecutar comandos SLQ arbitrarios mediante el parámetro hide_email. • http://marc.info/?l=bugtraq&m=107340481804110&w=2 http://secunia.com/advisories/10567 http://www.osvdb.org/3508 http://www.securityfocus.com/bid/9363 https://exchange.xforce.ibmcloud.com/vulnerabilities/14146 •
CVE-2004-0034
https://notcve.org/view.php?id=CVE-2004-0034
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php. Múltiples vulneravilidades de secuencias de comandos en sitios cruzados (XSS) en Phorum 3.4.5 y anteriores pemite a atacantes inyectar código HTML o script web arbitrario mediante la función phorum_check_xss en common.php, la variable EditError en profile.php, y la variable Error en login.php. • http://marc.info/?l=bugtraq&m=107340481804110&w=2 http://phorum.org http://secunia.com/advisories/10567 http://www.osvdb.org/3434 http://www.osvdb.org/3506 http://www.osvdb.org/3510 http://www.securityfocus.com/bid/9361 http://www.securitytracker.com/id?1008633 https://exchange.xforce.ibmcloud.com/vulnerabilities/14145 •
CVE-2003-1467
https://notcve.org/view.php?id=CVE-2003-1467
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. • http://securityreason.com/securityalert/3288 http://www.securityfocus.com/archive/1/321310 http://www.securityfocus.com/bid/7572 http://www.securityfocus.com/bid/7573 http://www.securityfocus.com/bid/7576 http://www.securityfocus.com/bid/7577 http://www.securityfocus.com/bid/7584 https://exchange.xforce.ibmcloud.com/vulnerabilities/12487 https://exchange.xforce.ibmcloud.com/vulnerabilities/12502 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2003-0283 – Phorum 3.4.x - 'Message Form' HTML Injection
https://notcve.org/view.php?id=CVE-2003-0283
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail. Vulnerabilidad de secuencias de comandos en sitios cruzados en Phorum anterior a la 3.4.3 permite que atacantes remotos inyecten script web arbitrario y tags HTML mediante un mensaje con una "<<" anterior a un nombre de etiqueta en (1) asunto, (2) nombre de autor, ó (3) dirección de correo electrónico del autor. • https://www.exploit-db.com/exploits/22579 http://marc.info/?l=bugtraq&m=105251043821533&w=2 http://marc.info/?l=bugtraq&m=105251421925394&w=2 http://www.securityfocus.com/bid/7545 https://exchange.xforce.ibmcloud.com/vulnerabilities/11974 •
CVE-2000-1232
https://notcve.org/view.php?id=CVE-2000-1232
upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method. • http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html http://hispahack.ccc.de/mi020.html http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm •