← Back

CVE-2006-3611

nvd nist
Published: Jul 18, 2006Modified: Apr 16, 2026

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:N
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into a log file, which is then included by pm.php.

Affected (62)

Products: Phorum: Phorum
1 product
Phorum
Configuration A
62 vulnerable
Vulnerable SoftwareAffected Versions
Phorum
Up to 5.1.14
Version 3.0.7
Version 3.1.1
Version 3.1.1_pre
Version 3.1.1_rc2
Version 3.1.1a
Version 3.1.2
Version 3.1
Version 3.2.2
Version 3.2.3
Version 3.2.3a
Version 3.2.3b
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2
Version 3.3.1
Version 3.3.1a
Version 3.3.2
Version 3.3.2a
Version 3.3.2b3
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.8a
Version 3.4
Version 4.3.7
Version 5.0.0_alpha
Version 5.0.10
Version 5.0.11
Version 5.0.12
Version 5.0.13
Version 5.0.13a
Version 5.0.14
Version 5.0.14a
Version 5.0.15
Version 5.0.15a
Version 5.0.16
Version 5.0.17
Version 5.0.17a
Version 5.0.18
Version 5.0.19
Version 5.0.1_alpha
Version 5.0.20
Version 5.0.2_alpha
Version 5.0.3_beta
Version 5.0.4_beta
Version 5.0.4a_beta
Version 5.0.5_beta
Version 5.0.6_beta
Version 5.0.7_beta
Version 5.0.7a_beta
Version 5.0.8_rc
Version 5.0.9
Version 5.1.13

Timeline

No history available yet.