First published: Wed Dec 31 2003(Updated: )
Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phorum | =3.4 | |
Phorum | =3.4.2 | |
Phorum | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1466 is a vulnerability in Phorum versions 3.4 to 3.4.2 that allows remote attackers to use the application as a connection proxy to external sites.
Phorum versions 3.4, 3.4.1, and 3.4.2 are affected by CVE-2003-1466.
CVE-2003-1466 can lead to unauthorized access and the potential for misuse of the Phorum service as a proxy.
To fix CVE-2003-1466, upgrade Phorum to a version that is not affected, and implement proper input validation.
CVE-2003-1466 is considered a moderate severity vulnerability, but its impact may vary depending on the environment.