PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter.  NOTE: this issue has been disputed by the vendor, who states "common.php is checked on the very first line of non-comment code that it is not being called directly. It has been this way in all 5.x version of Phorum."  CVE analysis concurs with the vendor
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2006-06-16 10:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-3053
Mitre link : CVE-2006-3053
CVE.ORG link : CVE-2006-3053
JSON object : View
Products Affected
                phorum
- phorum
CWE
                