PT-2007-1870 · Simple Machines · Simple Machines Forum

Publicado

2007-01-22

·

Atualizado

2018-10-16

·

CVE-2007-0399

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) version 1.1 RC3
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the index.php file of Simple Machines Forum (SMF). These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. This can be achieved via the recipient or BCC field when selecting send in a pm action.
Recommendations For Simple Machines Forum (SMF) version 1.1 RC3, consider disabling the pm action functionality until a patch is available to prevent exploitation of the XSS vulnerabilities in the recipient and BCC fields. Restrict access to the index.php file to minimize the risk of arbitrary web script or HTML injection.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0399

Produtos afetados

Simple Machines Forum