Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:22:29

Updated: 2022-10-03T16:22:29

Reserved: 2022-10-03T00:00:00


Link: CVE-2000-1229

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2000-12-31T05:00:00.000

Modified: 2008-09-05T20:22:58.793


Link: CVE-2000-1229

JSON object: View

cve-icon Redhat Information

No data.