CVE-2000-1234
Phorum 3.0.7 - Unauthenticated Email Spoofing via Mod and ForumName Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-1234. PoCs published by Max Vision.
AI-analyzed exploit summary The exploit describes a vulnerability in Phorum's violation.php3 script that allows remote users to send arbitrary emails via crafted URL parameters. The issue stems from improper handling of user-supplied input, enabling email relaying without authentication.
Description
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.
Exploits (1)
The exploit describes a vulnerability in Phorum's violation.php3 script that allows remote users to send arbitrary emails via crafted URL parameters. The issue stems from improper handling of user-supplied input, enabling email relaying without authentication.