CVE-2005-1404

MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myphp_forum:myphp_forum:1.0:*:*:*:*:*:*:*
cpe:2.3:a:myphp_forum:myphp_forum:2.0:*:*:*:*:*:*:*
cpe:2.3:a:myphp_forum:myphp_forum:3.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:57

Type Values Removed Values Added
References () http://secunia.com/advisories/15166 - Vendor Advisory () http://secunia.com/advisories/15166 - Vendor Advisory
References () http://www.osvdb.org/15902 - Exploit, Patch, Vendor Advisory () http://www.osvdb.org/15902 - Exploit, Patch, Vendor Advisory
References () http://www.osvdb.org/15903 - Exploit, Vendor Advisory () http://www.osvdb.org/15903 - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/13429 - () http://www.securityfocus.com/bid/13429 -
References () http://www.securityfocus.com/bid/13430 - () http://www.securityfocus.com/bid/13430 -
References () http://www.securityfocus.org/archive/1/397025 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.org/archive/1/397025 - Exploit, Patch, Vendor Advisory

Information

Published : 2005-05-03 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2005-1404

Mitre link : CVE-2005-1404

CVE.ORG link : CVE-2005-1404


JSON object : View

Products Affected

myphp_forum

  • myphp_forum