First published: Wed Dec 31 2003(Updated: )
Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phorum Phorum | =3.4 | |
Phorum Phorum | =3.4.2 | |
Phorum Phorum | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.