← Vulnerability feed

Vulnerability record · CVE-2005-2651 · published 23 August 2005

CVE-2005-2651: Phpoutsourcing zorum vulnerability

Phpoutsourcing · Zorum

gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter.

7.5 CVSS 2.0 High EPSS 5.1% · top 8.0%
7.5CVSS 2.0 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2651 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2006-5431Phpoutsourcing zorum vulnerabilityPHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute arbitrary …EPSS 2.5%7.5CVE-2006-3332Phpoutsourcing zorum vulnerabilitySQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3…EPSS 1.2%7.5CVE-2005-4619Phpoutsourcing zorum vulnerabilitySQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via …EPSS 1.1%7.5CVE-2005-0676Phpoutsourcing zorum vulnerabilityindex.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.EPSS 1.4%5.0CVE-2005-2652Phpoutsourcing zorum vulnerabilityZorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.ph…EPSS 1.6%5.0CVE-2005-0677Phpoutsourcing zorum vulnerabilityindex.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.EPSS 1.1%5.0CVE-2003-1089Phpoutsourcing zorum vulnerabilityindex.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a P…EPSS 2.9%4.3CVE-2005-0675Phpoutsourcing zorum vulnerabilityCross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list o…EPSS 0.99%

Source: NIST National Vulnerability Database (record CVE-2005-2651), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.