CVE-2003-1466: High severity Phorum Phorum vulnerability
Published Dec 31, 2003
·Updated
Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.
Affected Software
3 affected components
Phorum Phorum=3.4
Phorum Phorum=3.4.2
Phorum Phorum=3.4.1
Remediation
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Oct 25, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is CVE-2003-1466?
CVE-2003-1466 is a vulnerability in Phorum versions 3.4 to 3.4.2 that allows remote attackers to use the application as a connection proxy to external sites.
2
What versions of Phorum are affected by CVE-2003-1466?
Phorum versions 3.4, 3.4.1, and 3.4.2 are affected by CVE-2003-1466.
3
What potential risks does CVE-2003-1466 pose?
CVE-2003-1466 can lead to unauthorized access and the potential for misuse of the Phorum service as a proxy.
4
How do I fix CVE-2003-1466?
To fix CVE-2003-1466, upgrade Phorum to a version that is not affected, and implement proper input validation.
5
Is CVE-2003-1466 a high severity vulnerability?
CVE-2003-1466 is considered a moderate severity vulnerability, but its impact may vary depending on the environment.