CVE-2000-1229EPSS p74.4%

CVE-2000-1229CVE-2000-1229

phorum / phorum

Description

Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.

Scoring

CVSS 5.0 ()
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS1.56% probability of exploitation · percentile 74.4% · 2026-10-05T12:00:23Z
Last modified2026-09-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.