VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Jun 16, 2026

CVE-2002-0764

CVE-2002-0764

Description

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Phorum/Phorum2 versions
    cpe:2.3:a:phorum:phorum:3.3.2a:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phorum:phorum:3.3.2a:*:*:*:*:*:*:*
    • (no CPE)range: =3.3.2a

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.