VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2240

CVE-2004-2240

Description

Phorum 5.0.11 and earlier contain multiple SQL injection vulnerabilities in read.php and file.php, allowing remote attackers to manipulate SQL queries.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Phorum 5.0.11 and earlier contain multiple SQL injection vulnerabilities in read.php and file.php, allowing remote attackers to manipulate SQL queries.

Vulnerability

Phorum 5.0.11 and earlier are vulnerable to multiple SQL injection flaws. The first vector exists in read.php where the query string is not properly sanitized, allowing an attacker to inject arbitrary SQL. A second vector exists in file.php via unknown parameters. [2]

Exploitation

An unauthenticated remote attacker can exploit these vulnerabilities by sending a crafted HTTP request to read.php with malicious SQL in the query string, or by targeting the unknown vectors in file.php. No authentication or special privileges are required. [2]

Impact

Successful exploitation allows an attacker to modify SQL statements, potentially leading to unauthorized access to or manipulation of the Phorum database, including disclosure of sensitive data or alteration of forum content. [2]

Mitigation

The vendor has not released a specific patch version in the available references. Users should upgrade to a version later than 5.0.11, as later releases likely contain fixes. The Phorum project has since evolved, and the latest version should be used. [1] [2]

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Phorum/Phorum2 versions
    cpe:2.3:a:phorum:phorum:5.0.11:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phorum:phorum:5.0.11:*:*:*:*:*:*:*
    • (no CPE)range: <=5.0.11

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.