20020517 Phorum 3.3.2a remote command executionmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-05/0147.html CVE-2002-0764
Phorum 3.3.2a - Remote Command Execution
Record summary
CVE-2002-0764 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPhorum 3.3.2a - Remote Command ExecutionExploitDB exploitby markus arndtNot analyzed1 file
References
620020518 Phorum 3.3.2a has another bug for remote command executionmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-05/0153.html phorum-php-command-execution(9107)vdb entry
http://www.iss.net/security_center/static/9107.php phorum.orgConfirmation
http://www.phorum.org/ 4763vdb entry
http://www.securityfocus.com/bid/4763 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0764