← Back

CVE-2006-3053

nvd nist
Published: Jun 16, 2006Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter. NOTE: this issue has been disputed by the vendor, who states "common.php is checked on the very first line of non-comment code that it is not being called directly. It has been this way in all 5.x version of Phorum." CVE analysis concurs with the vendor

Affected (44)

Products: Phorum: Phorum
1 product
Phorum
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Phorum
Up to 5.1.13
Version 3.1.1
Version 3.1.1_pre
Version 3.1.1_rc2
Version 3.1.1a
Version 3.1.2
Version 3.1
Version 3.2.2
Version 3.2.3
Version 3.2.3a
Version 3.2.3b
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2
Version 3.3.1
Version 3.3.1a
Version 3.3.2
Version 3.3.2a
Version 3.3.2b3
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.8a
Version 3.4
Version 5.0.10
Version 5.0.11
Version 5.0.12
Version 5.0.13
Version 5.0.14
Version 5.0.15a
Version 5.0.16
Version 5.0.17a
Version 5.0.18
Version 5.0.3_beta
Version 5.0.7_beta
Version 5.0.9

References (10)

Timeline

No history available yet.