CVE Vulnerabilities

CVE-2006-3611

Published: Jul 18, 2006 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into a log file, which is then included by pm.php.

Affected Software

Name Vendor Start Version End Version
Phorum Phorum * 5.1.14 (including)
Phorum Phorum 3.0.7 (including) 3.0.7 (including)
Phorum Phorum 3.1 (including) 3.1 (including)
Phorum Phorum 3.1.1 (including) 3.1.1 (including)
Phorum Phorum 3.1.1_pre (including) 3.1.1_pre (including)
Phorum Phorum 3.1.1_rc2 (including) 3.1.1_rc2 (including)
Phorum Phorum 3.1.1a (including) 3.1.1a (including)
Phorum Phorum 3.1.2 (including) 3.1.2 (including)
Phorum Phorum 3.2 (including) 3.2 (including)
Phorum Phorum 3.2.2 (including) 3.2.2 (including)
Phorum Phorum 3.2.3 (including) 3.2.3 (including)
Phorum Phorum 3.2.3a (including) 3.2.3a (including)
Phorum Phorum 3.2.3b (including) 3.2.3b (including)
Phorum Phorum 3.2.4 (including) 3.2.4 (including)
Phorum Phorum 3.2.5 (including) 3.2.5 (including)
Phorum Phorum 3.2.6 (including) 3.2.6 (including)
Phorum Phorum 3.2.7 (including) 3.2.7 (including)
Phorum Phorum 3.2.8 (including) 3.2.8 (including)
Phorum Phorum 3.3.1 (including) 3.3.1 (including)
Phorum Phorum 3.3.1a (including) 3.3.1a (including)
Phorum Phorum 3.3.2 (including) 3.3.2 (including)
Phorum Phorum 3.3.2a (including) 3.3.2a (including)
Phorum Phorum 3.3.2b3 (including) 3.3.2b3 (including)
Phorum Phorum 3.4 (including) 3.4 (including)
Phorum Phorum 3.4.1 (including) 3.4.1 (including)
Phorum Phorum 3.4.2 (including) 3.4.2 (including)
Phorum Phorum 3.4.3 (including) 3.4.3 (including)
Phorum Phorum 3.4.4 (including) 3.4.4 (including)
Phorum Phorum 3.4.5 (including) 3.4.5 (including)
Phorum Phorum 3.4.6 (including) 3.4.6 (including)
Phorum Phorum 3.4.7 (including) 3.4.7 (including)
Phorum Phorum 3.4.8 (including) 3.4.8 (including)
Phorum Phorum 3.4.8a (including) 3.4.8a (including)
Phorum Phorum 4.3.7 (including) 4.3.7 (including)
Phorum Phorum 5.0.0_alpha (including) 5.0.0_alpha (including)
Phorum Phorum 5.0.1_alpha (including) 5.0.1_alpha (including)
Phorum Phorum 5.0.2_alpha (including) 5.0.2_alpha (including)
Phorum Phorum 5.0.3_beta (including) 5.0.3_beta (including)
Phorum Phorum 5.0.4_beta (including) 5.0.4_beta (including)
Phorum Phorum 5.0.4a_beta (including) 5.0.4a_beta (including)
Phorum Phorum 5.0.5_beta (including) 5.0.5_beta (including)
Phorum Phorum 5.0.6_beta (including) 5.0.6_beta (including)
Phorum Phorum 5.0.7_beta (including) 5.0.7_beta (including)
Phorum Phorum 5.0.7a_beta (including) 5.0.7a_beta (including)
Phorum Phorum 5.0.8_rc (including) 5.0.8_rc (including)
Phorum Phorum 5.0.9 (including) 5.0.9 (including)
Phorum Phorum 5.0.10 (including) 5.0.10 (including)
Phorum Phorum 5.0.11 (including) 5.0.11 (including)
Phorum Phorum 5.0.12 (including) 5.0.12 (including)
Phorum Phorum 5.0.13 (including) 5.0.13 (including)
Phorum Phorum 5.0.13a (including) 5.0.13a (including)
Phorum Phorum 5.0.14 (including) 5.0.14 (including)
Phorum Phorum 5.0.14a (including) 5.0.14a (including)
Phorum Phorum 5.0.15 (including) 5.0.15 (including)
Phorum Phorum 5.0.15a (including) 5.0.15a (including)
Phorum Phorum 5.0.16 (including) 5.0.16 (including)
Phorum Phorum 5.0.17 (including) 5.0.17 (including)
Phorum Phorum 5.0.17a (including) 5.0.17a (including)
Phorum Phorum 5.0.18 (including) 5.0.18 (including)
Phorum Phorum 5.0.19 (including) 5.0.19 (including)
Phorum Phorum 5.0.20 (including) 5.0.20 (including)
Phorum Phorum 5.1.13 (including) 5.1.13 (including)

References