PT-2000-2008 · Phorum · Phorum

Published

2000-12-31

·

Updated

2008-09-05

·

CVE-2000-1229

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Phorum version 3.0.7
Description A directory traversal issue allows remote Phorum administrators to read arbitrary files by using ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function. This causes the file to be displayed in admin.php3.
Recommendations For Phorum version 3.0.7, update the Master Settings administrative function to properly validate and sanitize the .langfile name field to prevent directory traversal attacks. As a temporary workaround, consider restricting access to the admin.php3 file and the Master Settings administrative function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1229

Affected Products

Phorum