VYPR
Unrated severityNVD Advisory· Published Dec 31, 2000· Updated Jun 16, 2026

CVE-2000-1229

CVE-2000-1229

Description

Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.

Affected products

2
  • Phorum/Phorum2 versions
    cpe:2.3:a:phorum:phorum:3.0.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phorum:phorum:3.0.7:*:*:*:*:*:*:*
    • (no CPE)range: = 3.0.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.