CVE-2000-1234: Medium severity Phorum Phorum vulnerability
Published Dec 31, 2000
·Updated
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.
Affected Software
1 affected component
Phorum Phorum=3.0.7
Remediation
Patch Available
Event History
Dec 31, 2000
CVE Published
05:00 AM
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1234?
CVE-2000-1234 is considered a high severity vulnerability due to its potential to allow remote attackers to exploit the system for sending spam.
2
How do I fix CVE-2000-1234?
To fix CVE-2000-1234, upgrade Phorum to a version higher than 3.0.7 where the vulnerability is patched.
3
What software is affected by CVE-2000-1234?
The affected software by CVE-2000-1234 includes Phorum version 3.0.7.
4
What type of attack does CVE-2000-1234 enable?
CVE-2000-1234 enables remote attackers to send emails to arbitrary addresses, effectively using the Phorum platform as a spam proxy.
5
Can CVE-2000-1234 affect my Phorum installation?
Yes, if you are running Phorum version 3.0.7, your installation is vulnerable to CVE-2000-1234.