CVE-2007-2250
Phorum < 5.1.20 - Information Disclosure via admin.php module[] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2250. PoCs published by Janek Vind.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in Phorum 5.1.20, including SQL injection, XSS, and unauthorized access due to insufficient input sanitization. It includes a proof-of-concept URL demonstrating an error triggered by array input in the 'module' parameter.
Description
admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.
Exploits (1)
The provided text describes multiple vulnerabilities in Phorum 5.1.20, including SQL injection, XSS, and unauthorized access due to insufficient input sanitization. It includes a proof-of-concept URL demonstrating an error triggered by array input in the 'module' parameter.