CVE-2003-1089

Zorum 3.4 - Information Disclosure via Invalid Parameter Names

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1089. PoCs published by Zone-h Security Team.

AI-analyzed exploit summary The provided text describes a path disclosure vulnerability in Zorum message board software, where a malformed HTTP request can reveal the installation path. No actual exploit code is present, only a description and an example URL.

Description

index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Zone-h Security Team · textwebappsphp
https://www.exploit-db.com/exploits/23018

The provided text describes a path disclosure vulnerability in Zorum message board software, where a malformed HTTP request can reveal the installation path. No actual exploit code is present, only a description and an example URL.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Zorum message board software
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106063199925536&w=2
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8396
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/12868
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013365

Scores

EPSS 0.0287
EPSS Percentile 85.0%

Details

Status published
Products (1)
phpoutsourcing/zorum 3.4
Published Dec 31, 2003
Tracked Since Feb 18, 2026