PT-2005-2401 · Myphp · Myphp Forum

Published

2005-05-03

·

Updated

2008-09-05

·

CVE-2005-1404

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: MyPHP Forum version 1.0
Description: The issue allows remote attackers to spoof the username. This can be achieved by modifying the nbuser parameter to "post.php" or the sender parameter to "privmsg.php".
Recommendations: For MyPHP Forum version 1.0, consider restricting access to the "post.php" and "privmsg.php" API endpoints to minimize the risk of exploitation. Avoid using the nbuser and sender parameters in these endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1404

Affected Products

Myphp Forum