PT-2002-1418 · Phorum · Phorum

Publicado

2002-05-03

·

Atualizado

2016-10-18

·

CVE-2002-0352

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phorum version 3.3.2
Description The issue allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the "stats.php" program, which does not require authentication.
Recommendations For Phorum version 3.3.2, consider restricting access to the stats.php program to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0352

Produtos afetados

Phorum