CVE-2006-3053 describes a disputed remote file inclusion vulnerability in PHORUM 5.1.13 and earlier, specifically within the common.php file. Attackers could potentially execute arbitrary PHP code by manipulating the PHORUM[http_path] parameter with a malicious URL. Despite the vendor's dispute and CVE analysis concurring with the vendor's assessment that common.php prevents direct calls, the CVSS score of 7.5 indicates a high severity, with low attack complexity and potential for partial confidentiality, integrity, and availability impacts. While there is an ExploitDB entry for PHORUM 3.x/5.x related to common.php remote file inclusion, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.13CPE matchmatch criteria | cpe:2.3:a:phorum:phorum:*:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:phorum:phorum:3.1:*:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:a:phorum:phorum:3.1.1:*:*:*:*:*:*:* | ||
3.1.1_preCPE matchmatch criteria | cpe:2.3:a:phorum:phorum:3.1.1_pre:*:*:*:*:*:*:* | ||
3.1.1_rc2CPE matchmatch criteria | cpe:2.3:a:phorum:phorum:3.1.1_rc2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.