CVE-2004-2243

Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phorum:phorum:4.3.7:*:*:*:*:*:*:*

History

20 Nov 2024, 23:52

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0999.html - () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0999.html -
References () http://securitytracker.com/id?1010219 - () http://securitytracker.com/id?1010219 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16215 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16215 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:52


NVD link : CVE-2004-2243

Mitre link : CVE-2004-2243

CVE.ORG link : CVE-2004-2243


JSON object : View

Products Affected

phorum

  • phorum