CVE-2000-1229
Low
No strong exploitation signal.
CVSS base
5.0
MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS — probability of exploitation (30 days)
1.6%
74.2th percentile
CISA KEV
Not listed
Weakness / dates
—
Published 2000-12-31 · modified 2026-09-23
CVSS breakdown
AV:N/AC:L/Au:N/C:P/I:N/A:N
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Authentication | N | None |
| Confidentiality | P | Partial |
| Integrity | N | None |
| Availability | N | None |
Timeline
- 2000-12-31 — Published (NVD)
- 2026-09-23 — Last modified (NVD)
Description
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
Affected
References
- exploit http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html
- http://hispahack.ccc.de/mi020.html
- http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm
- exploit http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html
- http://hispahack.ccc.de/mi020.html
- http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm