Vulnerabilities > CVE-2007-2249 - Input Validation vulnerability in Phorum

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phorum
exploit available

Summary

include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.

Exploit-Db

descriptionPhorum 5.1.20 include/controlcenter/users.php Multiple Method Remote Privilege Escalation. CVE-2007-2249. Webapps exploit for php platform
idEDB-ID:29889
last seen2016-02-03
modified2007-04-23
published2007-04-23
reporterJanek Vind
sourcehttps://www.exploit-db.com/download/29889/
titlePhorum 5.1.20 - include/controlcenter/users.php Multiple Method Remote Privilege Escalation