PHP.Phorum.Arbitrary.Code.Execution
Description
It indicates a possible exploit of remote file include vulnerability in Phorum.
Phorum is a PHP-based Web forum package for most Unix, Linux, and Windows systems. A remote php code inclusion vulnerability is reported in it that may allow an attacker to execute arbitrary server side script code on the affected system with privilege of web server process. Due to insufficient sanitization of user input by scripts plugin.php, admin.php, or del.php , an attacker may modify PHORUM[settings_dir] variable on a HTTP request to reference a URL on a remote web server that contains the malicious code. An attacker may exploit this to execute arbitrary code on the affected system and gain access to it.
Affected Products
Phorum Phorum 3.3.2 a and earlier versions.
Impact
Compromise of the affected system.
Recommended Actions
Phorum Phorum 3.3.2 b3 or later version.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |