SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.
2005-11-16T07:42:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | phorum | phorum | 5.0.0_alpha | Yes |
Application | phorum | phorum | 5.0.1_alpha | Yes |
Application | phorum | phorum | 5.0.2_alpha | Yes |
Application | phorum | phorum | 5.0.3_beta | Yes |
Application | phorum | phorum | 5.0.4_beta | Yes |
Application | phorum | phorum | 5.0.4a_beta | Yes |
Application | phorum | phorum | 5.0.5_beta | Yes |
Application | phorum | phorum | 5.0.6_beta | Yes |
Application | phorum | phorum | 5.0.7_beta | Yes |
Application | phorum | phorum | 5.0.7a_beta | Yes |
Application | phorum | phorum | 5.0.8_rc | Yes |
Application | phorum | phorum | 5.0.9 | Yes |
Application | phorum | phorum | 5.0.10 | Yes |
Application | phorum | phorum | 5.0.11 | Yes |
Application | phorum | phorum | 5.0.12 | Yes |
Application | phorum | phorum | 5.0.13 | Yes |
Application | phorum | phorum | 5.0.13a | Yes |
Application | phorum | phorum | 5.0.14 | Yes |
Application | phorum | phorum | 5.0.14a | Yes |
Application | phorum | phorum | 5.0.15 | Yes |
Application | phorum | phorum | 5.0.16 | Yes |
Application | phorum | phorum | 5.0.17 | Yes |
Application | phorum | phorum | 5.0.18 | Yes |
Application | phorum | phorum | 5.0.19 | Yes |
Application | phorum | phorum | 5.0.20 | Yes |