First published: Fri Dec 31 2004(Updated: )
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phorum | =5.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2240 is considered a critical vulnerability due to the potential for remote SQL injection attacks.
To fix CVE-2004-2240, upgrade to a version of Phorum later than 5.0.11 that has patched the SQL injection vulnerabilities.
Exploiting CVE-2004-2240 can allow attackers to execute arbitrary SQL commands on the database, leading to data manipulation or disclosure.
CVE-2004-2240 affects Phorum version 5.0.11 and earlier.
CVE-2004-2240 allows SQL injection through the query string in read.php and potentially other vectors in file.php.