CVE-2007-2338
Phorum < 5.1.20 - Cross-Site Request Forgery via Banlist Delete Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2338. PoCs published by Janek Vind.
AI-analyzed exploit summary The exploit describes an unauthorized access vulnerability in Phorum's banlist management due to insufficient input validation, allowing deletion of banlist entries via a crafted GET request. The issue stems from direct use of user-supplied input without proper sanitization or authorization checks.
Description
Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.
Exploits (1)
The exploit describes an unauthorized access vulnerability in Phorum's banlist management due to insufficient input validation, allowing deletion of banlist entries via a crafted GET request. The issue stems from direct use of user-supplied input without proper sanitization or authorization checks.