7.5

CVE-2004-2243

Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php.  NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhorumPhorum Version4.3.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.53% 0.715
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0999.html
http://securitytracker.com/id?1010219
https://exchange.xforce.ibmcloud.com/vulnerabilities/16215