CVE-2004-1938: SQL Injection
Published Apr 19, 2004
·Updated
SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorumuriauth parameter to list.php.
Affected Software
2 affected components
Phorum Phorum=3.4.7
Phorum Phorum=3.4.8
Remediation
Patch Available
Patch Available
Event History
Apr 19, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1938?
CVE-2004-1938 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2004-1938?
To fix CVE-2004-1938, upgrade Phorum to version 3.4.9 or later.
3
What software versions are affected by CVE-2004-1938?
CVE-2004-1938 affects Phorum versions 3.4.7 and 3.4.8.
4
What type of attack does CVE-2004-1938 involve?
CVE-2004-1938 involves an SQL injection attack that allows remote execution of arbitrary SQL commands.
5
Is CVE-2004-1938 known to be exploited in the wild?
There have been reports of exploitation attempts for CVE-2004-1938 in the wild.