SCAN: Phorum Violation Access

This signature detects attempts to access the vulnerable violation.php3 script in Phorum, a free, open source forum/discussion package for Web sites. Attackers can send maliciously crafted URL requests to violation.php3 to arbitrarily relay e-mail through the host MTA.

Extended Description

Phorum is a freely available, open source package originally written by Brian Moon. The package is designed to add enhanced features to a web page, allowing users to interact through bulletin board style chats forums and discussions. A problem with the Phorum package could allow remote users to arbitrarily relay email. Due to the way violation.php3 handles URL's as arguments, it is possible to create a custom crafted URL request to the script which will allow a remote user to send email through the hosts MTA. This email will then be delivered to the specified person with the appearance of coming from the web host. This problem makes it possible for a user with malicious intentions to socially engineer, mailbomb, or spam from the web host, and potentially get the host blacklisted in one of such lists.

Affected Products

Brian_moon phorum

Short Name
SCAN:MISC:HTTP:VIOLATION-ACCS
Severity
Info
Recommended
False
Recommended Action
None
Category
SCAN
Keywords
Access Phorum Violation bid:2272
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Rarely
Vendors

Brian_moon

Found a potential security threat?