PT-2011-2894 · Simple Machines · Simple Machines Forum
Steven M. Christey
·
Publicado
2011-06-21
·
Atualizado
2012-12-20
·
CVE-2011-1130
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machines Forum (SMF) versions prior to 1.1.13
Simple Machines Forum (SMF) versions 2.x prior to 2.0 RC5
Description
The issue is related to improper validation of the
start parameter, which could allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value. This is related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.Recommendations
For Simple Machines Forum (SMF) versions prior to 1.1.13, update to version 1.1.13 or later.
For Simple Machines Forum (SMF) versions 2.x prior to 2.0 RC5, update to version 2.0 RC5 or later.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simple Machines Forum