CVE-2002-0764: High severity Phorum Phorum vulnerability
Published Jul 26, 2002
·Updated
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settingsdir] variable to point to a directory that contains a PHP file with the commands.
Affected Software
1 affected component
Phorum Phorum=3.3.2a
Remediation
Patch Available
Patch Available
Event History
Jul 26, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0764?
CVE-2002-0764 is considered a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2002-0764?
To fix CVE-2002-0764, upgrade to a later version of Phorum that has addressed this vulnerability.
3
What systems are affected by CVE-2002-0764?
CVE-2002-0764 affects Phorum version 3.3.2a.
4
What types of attacks can exploit CVE-2002-0764?
CVE-2002-0764 can be exploited by sending crafted HTTP requests that manipulate the PHORUM[settings_dir] variable.
5
Is CVE-2002-0764 related to any specific features of Phorum?
CVE-2002-0764 specifically exploits the plugin.php, admin.php, or del.php files within Phorum.