CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10666  CVE-2004-2240  Candidate  Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.  Assigned (20050717)  None (candidate not yet proposed)    View
10667  CVE-2004-2241  Candidate  Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor"s patch.  Assigned (20050717)  None (candidate not yet proposed)    View
10668  CVE-2004-2242  Candidate  Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.  Assigned (20050717)  None (candidate not yet proposed)    View
13484  CVE-2005-2278  Candidate  Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.  Assigned (20050717)  None (candidate not yet proposed)    View
10669  CVE-2004-2243  Candidate  Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 19092 of 20943, showing 5 records out of 104715 total, starting on record 95456, ending on 95460

Actions