CVE-2004-2243 Information

Description

Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7 but this may be erroneous.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0999.html http://securitytracker.com/id?1010219 https://exchange.xforce.ibmcloud.com/vulnerabilities/16215

Share on: