CVE-2007-2250: Medium severity Phorum Phorum vulnerability
Published Apr 25, 2007
·Updated
admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.
Affected Software
1 affected component
Phorum Phorum<=5.1.20
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 25, 2007
CVE Published
04:19 PM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2250?
CVE-2007-2250 has a medium severity rating due to its potential for path disclosure, which can aid attackers in exploiting the application.
2
How do I fix CVE-2007-2250?
To fix CVE-2007-2250, upgrade Phorum to version 5.1.22 or later, which addresses this vulnerability.
3
What is the impact of CVE-2007-2250?
The impact of CVE-2007-2250 is that it allows remote attackers to disclose the full file path of the server.
4
Who is affected by CVE-2007-2250?
CVE-2007-2250 affects users of Phorum versions prior to 5.1.22.
5
Is CVE-2007-2250 easily exploitable?
Yes, CVE-2007-2250 is considered easily exploitable due to its reliance on a simple parameter manipulation in the URL.