PT-2011-2891 · Simple Machines · Simple Machines Forum

Hanno Böck

·

Published

2011-06-21

·

Updated

2011-06-29

·

CVE-2011-1127

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) versions 1.1.x through 1.1.12 Simple Machines Forum (SMF) versions 2.x through 2.0 RC4
Description The issue is related to the SSI.php file in Simple Machines Forum (SMF), which does not properly restrict guest access. This allows remote attackers to have an unspecified impact via unknown vectors.
Recommendations For Simple Machines Forum (SMF) versions 1.1.x through 1.1.12, update to version 1.1.13 or later. For Simple Machines Forum (SMF) versions 2.x through 2.0 RC4, update to version 2.0 RC5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1127

Affected Products

Simple Machines Forum