CVE-2002-0764 Information
Feb 14, 2021
cve
Description
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php (2) admin.php or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.
Reference
http://archives.neohapsis.com/archives/bugtraq/2002-05/0147.html http://archives.neohapsis.com/archives/bugtraq/2002-05/0153.html http://www.iss.net/security_center/static/9107.php http://www.phorum.org/ http://www.securityfocus.com/bid/4763
Share on: