PT-2000-2013 · Phorum · Phorum

Published

2000-12-31

·

Updated

2008-09-05

·

CVE-2000-1234

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phorum version 3.0.7
Description The issue allows remote attackers to send e-mails to arbitrary addresses, potentially using Phorum as a spam proxy. This is achieved by setting the Mod and ForumName parameters in the violation.php3 file.
Recommendations For Phorum version 3.0.7, consider restricting access to the violation.php3 file to prevent unauthorized use, and avoid using the Mod and ForumName parameters in this context until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1234

Affected Products

Phorum