CVE-2005-1404 Information

Description

MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.

Reference

http://secunia.com/advisories/15166 http://www.osvdb.org/15902 http://www.osvdb.org/15903 http://www.securityfocus.com/bid/13429 http://www.securityfocus.com/bid/13430 http://www.securityfocus.org/archive/1/397025

Share on: