Vulnerability Description
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phorum | Phorum | 4.3.7 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0999.html
- http://securitytracker.com/id?1010219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16215
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0999.html
- http://securitytracker.com/id?1010219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16215
FAQ
What is CVE-2004-2243?
CVE-2004-2243 is a vulnerability with a CVSS score of 7.5 (HIGH). Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected vers...
How severe is CVE-2004-2243?
CVE-2004-2243 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2243?
Check the references section above for vendor advisories and patch information. Affected products include: Phorum Phorum.