Phorum User Information Disclosure Vulnerability
BID:4226
Info
Phorum User Information Disclosure Vulnerability
| Bugtraq ID: | 4226 |
| Class: | Design Error |
| CVE: |
CVE-2002-0352 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Reported by Agricola <[email protected]>. |
| Vulnerable: |
Phorum Phorum 3.3.2 |
| Not Vulnerable: | |
Discussion
Phorum User Information Disclosure Vulnerability
Phorum is a PHP based web forums package. Due to an error in a administrative script, any user can view the most active user's information.
Reportedly, this issue results because of the 'stats.php' script residing in the admin directory. 'stats.php' has no privilege restrictions, as a result a user can retrieve this file and reveal a list of the most active users and their email addresses.
Earlier versions of Phorum may share this vulnerability. This has not been confirmed.
Phorum is a PHP based web forums package. Due to an error in a administrative script, any user can view the most active user's information.
Reportedly, this issue results because of the 'stats.php' script residing in the admin directory. 'stats.php' has no privilege restrictions, as a result a user can retrieve this file and reveal a list of the most active users and their email addresses.
Earlier versions of Phorum may share this vulnerability. This has not been confirmed.
Exploit / POC
Phorum User Information Disclosure Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Phorum User Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.