| Vulnerability Name: | CVE-2003-1486 (CCN-12499) | ||||||||
| Assigned: | 2003-05-13 | ||||||||
| Published: | 2003-05-13 | ||||||||
| Updated: | 2017-07-29 | ||||||||
| Summary: | Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-200 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Tue May 13 2003 - 02:17:37 CDT Phorum Vulnerabilities Source: MITRE Type: CNA CVE-2003-1486 Source: CCN Type: Phorum Web site Phorum.org Source: SREASON Type: UNKNOWN 3288 Source: CCN Type: OSVDB ID: 13290 Phorum Multiple Script Path Disclosure Source: BUGTRAQ Type: UNKNOWN 20030513 Phorum Vulnerabilities Source: BID Type: Patch 7571 Source: CCN Type: BID-7571 Phorum Multiple Path Disclosure Vulnerabilities Source: XF Type: UNKNOWN phorum-multiple-path-disclosure(12499) Source: XF Type: UNKNOWN phorum-multiple-path-disclosure(12499) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||