5
CVSSv2

CVE-2003-1486

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Phorum 3.4 up to and including 3.4.2 allows remote malicious users to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

phorum phorum 3.4.2

phorum phorum 3.4

phorum phorum 3.4.1