CVE-2006-3611

Phorum 5 - Authenticated Directory Traversal and Arbitrary File Execution via GLOBALS[template] Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3611. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets a local file inclusion vulnerability in Phorum 5, allowing arbitrary command execution via log poisoning. It requires authentication and specific PHP configurations (register_globals=On, magic_quotes_gpc=Off).

Description

Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into a log file, which is then included by pm.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/2008

This exploit targets a local file inclusion vulnerability in Phorum 5, allowing arbitrary command execution via log poisoning. It requires authentication and specific PHP configurations (register_globals=On, magic_quotes_gpc=Off).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Phorum 5
Auth required
Prerequisites: Valid user credentials · PHP register_globals=On · PHP magic_quotes_gpc=Off · Writable log files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Various Sources x_refsource_misc
http://www.phorum.org/phorum5/read.php?14%2C114358
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2794
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439976/100/0/threaded

Scores

EPSS 0.0212
EPSS Percentile 79.5%

Details

Status published
Products (50)
phorum/phorum 3.0.7
phorum/phorum 3.1
phorum/phorum 3.1.1
phorum/phorum 3.1.1_pre
phorum/phorum 3.1.1_rc2
phorum/phorum 3.1.1a
phorum/phorum 3.1.2
phorum/phorum 3.2
phorum/phorum 3.2.2
phorum/phorum 3.2.3
... and 40 more
Published Jul 18, 2006
Tracked Since Feb 18, 2026