Vulnerabilities > CVE-2005-0345 - Unspecified vulnerability in PHP Fusion PHP Fusion 4.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
php-fusion
nessus
exploit available

Summary

viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.

Vulnerable Configurations

Part Description Count
Application
Php_Fusion
1

Exploit-Db

descriptionPHP-Fusion 4.0 Viewthread.PHP Information Disclosure Vulnerbility. CVE-2005-0345. Webapps exploit for php platform
idEDB-ID:25089
last seen2016-02-03
modified2005-02-08
published2005-02-08
reporterTheGreatOne2176
sourcehttps://www.exploit-db.com/download/25089/
titlePHP-Fusion 4.0 Viewthread.PHP Information Disclosure Vulnerbility

Nessus

NASL familyCGI abuses
NASL idPHP_FUSION_INFO_LEAK.NASL
descriptionA vulnerability exists in the version of PHP-Fusion installed on the remote host that may allow an attacker to read the contents of arbitrary forums and threads, regardless of the attacker
last seen2020-06-01
modified2020-06-02
plugin id16336
published2005-02-09
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/16336
titlePHP-Fusion < 5.00 viewthread.php Arbitrary Message Thread / Forum Access