← Vulnerability feed

Vulnerability record · CVE-2003-1487 · published 31 December 2003

CVE-2003-1487: Phorum improper input validation vulnerability

Phorum · Phorum

Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.

10.0 CVSS 2.0 High EPSS 8.0% · top 5.4% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
8.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1487 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-2338Phorum vulnerabilityCross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized …EPSS 8.7%7.5CVE-2007-2339Phorum vulnerabilityMultiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients…EPSS 1.9%7.5CVE-2006-6550Phorum vulnerabilityPHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…EPSS 2.2%7.5CVE-2006-3249Phorum vulnerabilitySQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page paramet…EPSS 1.2%7.5CVE-2006-3053Phorum vulnerabilityPHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…EPSS 2.9%7.5CVE-2004-2110Phorum vulnerabilitySQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email param…EPSS 1.1%7.5CVE-2004-2240Phorum vulnerabilityMultiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.…EPSS 1.6%7.5CVE-2004-2243Phorum vulnerabilityPhorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demon…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2003-1487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.