Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-07-14T04:00:00Z

Updated: 2024-09-16T17:08:11.598Z

Reserved: 2005-07-14T00:00:00Z

Link: CVE-2000-1229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2000-12-31T05:00:00.000

Modified: 2008-09-05T20:22:58.793

Link: CVE-2000-1229

cve-icon Redhat

No data.