CVE-2002-0352: Medium severity phorum phorum vulnerability
Published May 3, 2002
·Updated
Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication.
Affected Software
1 affected component
Phorum Phorum=3.3.2
Event History
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0352?
CVE-2002-0352 has a medium severity rating due to the exposure of user email addresses.
2
How do I fix CVE-2002-0352?
To fix CVE-2002-0352, implement access controls to restrict access to the stats.php program.
3
Which software versions are affected by CVE-2002-0352?
CVE-2002-0352 affects Phorum version 3.3.2.
4
What impact does CVE-2002-0352 have on user privacy?
CVE-2002-0352 allows remote attackers to retrieve the email addresses of the most active users, compromising their privacy.
5
How can I detect if my system is affected by CVE-2002-0352?
You can detect if your system is affected by CVE-2002-0352 by checking for the Phorum version 3.3.2 and verifying access to stats.php.