CVE-2007-2339: SQL Injection
Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2339?
CVE-2007-2339 is considered a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2007-2339?
To fix CVE-2007-2339, upgrade Phorum to version 5.1.22 or later, where the vulnerabilities are addressed.
What types of attacks are possible with CVE-2007-2339?
CVE-2007-2339 allows remote attackers to execute arbitrary SQL commands, potentially compromising database integrity.
Which versions of Phorum are affected by CVE-2007-2339?
CVE-2007-2339 affects Phorum versions prior to 5.1.22.
Is authentication required to exploit CVE-2007-2339?
No authentication is required to exploit CVE-2007-2339, making it particularly dangerous for vulnerable installations.