Phpoutsourcing / Zorum
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2002-2350 | Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject arbitrary web scrip… | MEDIUM | 4.3 | Oct 29, 2007 |
| CVE-2006-5431 | PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute arbitrary PHP code v… | HIGH | 7.5 | Oct 20, 2006 |
| CVE-2006-3333 | Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified para… | LOW | 2.6 | Jun 30, 2006 |
| CVE-2006-3332 | SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid,… | HIGH | 7.5 | Jun 30, 2006 |
| CVE-2005-4619 | SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid… | HIGH | 7.5 | Jan 5, 2006 |
| CVE-2005-2652 | Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.php, (4) bla… | MEDIUM | 5.0 | Aug 21, 2005 |
| CVE-2005-2651 | gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter. | HIGH | 7.5 | Aug 21, 2005 |
| CVE-2005-0677 | index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter. | MEDIUM | 5.0 | Mar 7, 2005 |
| CVE-2005-0676 | index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability. | HIGH | 7.5 | Mar 7, 2005 |
| CVE-2005-0675 | Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) from… | MEDIUM | 4.3 | Mar 7, 2005 |
| CVE-2003-1089 | index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error m… | MEDIUM | 5.0 | Mar 7, 2005 |
| CVE-2003-1088 | Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method param… | MEDIUM | 4.3 | Mar 7, 2005 |
Showing 1 to 12 of 12 CVEs