PT-2000-2013 · Phorum · Phorum

Publicado

2000-12-31

·

Atualizado

2008-09-05

·

CVE-2000-1234

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phorum version 3.0.7
Description The issue allows remote attackers to send e-mails to arbitrary addresses, potentially using Phorum as a spam proxy. This is achieved by setting the Mod and ForumName parameters in the violation.php3 file.
Recommendations For Phorum version 3.0.7, consider restricting access to the violation.php3 file to prevent unauthorized use, and avoid using the Mod and ForumName parameters in this context until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-1234

Produtos afetados

Phorum