Vulnerabilities > Phorum > Critical

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1487 Improper Input Validation vulnerability in Phorum 3.4/3.4.1/3.4.2
Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.
network
low complexity
phorum CWE-20
critical
10.0