MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Myphp_forum | Myphp_forum | 1.0 (including) | 1.0 (including) |
Myphp_forum | Myphp_forum | 2.0 (including) | 2.0 (including) |
Myphp_forum | Myphp_forum | 3.0 (including) | 3.0 (including) |