CVE-2004-1518: SQL Injection
SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forumid parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1518?
CVE-2004-1518 is considered to be of high severity due to the potential for remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2004-1518?
To fix CVE-2004-1518, upgrade Phorum to version 5.0.13 or later, which addresses this SQL injection vulnerability.
Which versions of Phorum are affected by CVE-2004-1518?
CVE-2004-1518 affects Phorum versions 5.0.12 and earlier, including versions 5.0.10, 5.0.11, 5.0.9, and 5.0.7_beta.
Can CVE-2004-1518 be exploited remotely?
Yes, CVE-2004-1518 can be exploited remotely by authenticated users to perform SQL injection attacks.
What impact does CVE-2004-1518 have on Phorum applications?
CVE-2004-1518 can lead to unauthorized data access and manipulation, posing significant security risks to Phorum applications.