CVE-2006-3053: High severity Phorum Phorum vulnerability
DISPUTED PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[httppath] parameter. NOTE: this issue has been disputed by the vendor, who states "common.php is checked on the very first line of non-comment code that it is not being called directly. It has been this way in all 5.x version of Phorum." CVE analysis concurs with the vendor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3053?
The severity of CVE-2006-3053 is considered medium, as it allows remote attackers to execute arbitrary PHP code.
How do I fix CVE-2006-3053?
To fix CVE-2006-3053, update your PHORUM installation to version 5.1.14 or later to mitigate the remote file inclusion vulnerability.
Which versions of PHORUM are affected by CVE-2006-3053?
CVE-2006-3053 affects PHORUM version 5.1.13 and earlier versions.
What types of attacks can be executed using CVE-2006-3053?
Using CVE-2006-3053, remote attackers can potentially execute arbitrary PHP code on the server, leading to a breach of confidentiality or integrity.
Is there a vendor response to CVE-2006-3053?
Yes, the vendor has disputed the issue, claiming that common.php is checked at the first level, which may mitigate the vulnerability.