Vulnerabilities > CVE-2004-2243 - Remote Security vulnerability in Phorum 4.3.7
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |