Phorum 5.0.11 - 'Read.php' SQL Injection

EDB-ID:

25919

CVE:

N/A




Platform:

PHP

Date:

2004-10-24


source: https://www.securityfocus.com/bid/14095/info

Phoroum is prone to SQL injection attacks. Insufficient sanitization of user input may allow a malicious user to manipulate the structure and logic of database queries.

Successful exploitation could allow the attacker to compromise security properties of the application and the database. Possible consequences include unauthorized access to the application and database.

This issue has been reported to exist in Phorum 5.0.11. Earlier versions may also be affected. 

http://www.example.com/read.php?1,[MALICIOUS_SQL_CODE],newer