CVE-2003-1486 Information
Feb 14, 2021
cve
Description
Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php (2) quick_listrss.php (3) purge.php (4) news.php (5) memberlist.php (6) forum_listrss.php (7) forum_list_rdf.php (8) forum_list.php or (9) move.php which leaks the information in an error message.
Reference
http://securityreason.com/securityalert/3288 http://www.securityfocus.com/archive/1/321310 http://www.securityfocus.com/bid/7571 https://exchange.xforce.ibmcloud.com/vulnerabilities/12499
Share on: