VulnerabilityModified
CVE-2005-1404
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
MEDIUM 5.0EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- myphp forum/myphp forum
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/15166Vendor Advisory
- http://www.osvdb.org/15902Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/15903Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/13429
- http://www.securityfocus.com/bid/13430
- http://www.securityfocus.org/archive/1/397025Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/15166Vendor Advisory
- http://www.osvdb.org/15902Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/15903Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/13429
- http://www.securityfocus.com/bid/13430
- http://www.securityfocus.org/archive/1/397025Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.