Total vulnerabilities in the database
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
CVSS v2:
No CWE or OWASP classifications available.