NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72616 | CVE-2004-2239 | Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72617 | CVE-2004-2240 | Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72618 | CVE-2004-2241 | Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72619 | CVE-2004-2242 | Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72620 | CVE-2004-2243 | Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 2076 of 17672, showing 5 records out of 88360 total, starting on record 10376, ending on 10380