CVE-2004-0035: SQL Injection
Published Jan 20, 2004
·Updated
SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hideemail parameter.
Affected Software
1 affected component
Phorum Phorum<=3.4.5
Event History
Jan 20, 2004
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0035?
CVE-2004-0035 is considered a critical vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2004-0035?
To fix CVE-2004-0035, update to Phorum version 3.4.6 or later, which patches the SQL injection vulnerability.
3
What software is affected by CVE-2004-0035?
CVE-2004-0035 affects Phorum versions 3.4.5 and earlier.
4
Can CVE-2004-0035 lead to data compromise?
Yes, CVE-2004-0035 can lead to unauthorized access to the database and potential data compromise.
5
What is SQL injection in the context of CVE-2004-0035?
SQL injection in CVE-2004-0035 allows attackers to manipulate SQL queries through the 'hide_email' parameter in the register.php file.