Get Demo
admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.