PT-2005-2401 · Myphp · Myphp Forum

Publicado

2005-05-03

·

Atualizado

2008-09-05

·

CVE-2005-1404

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: MyPHP Forum version 1.0
Description: The issue allows remote attackers to spoof the username. This can be achieved by modifying the nbuser parameter to "post.php" or the sender parameter to "privmsg.php".
Recommendations: For MyPHP Forum version 1.0, consider restricting access to the "post.php" and "privmsg.php" API endpoints to minimize the risk of exploitation. Avoid using the nbuser and sender parameters in these endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1404

Produtos afetados

Myphp Forum