PT-2011-2894 · Simple Machines · Simple Machines Forum

Steven M. Christey

·

Published

2011-06-21

·

Updated

2012-12-20

·

CVE-2011-1130

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) versions prior to 1.1.13 Simple Machines Forum (SMF) versions 2.x prior to 2.0 RC5
Description The issue is related to improper validation of the start parameter, which could allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value. This is related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.
Recommendations For Simple Machines Forum (SMF) versions prior to 1.1.13, update to version 1.1.13 or later. For Simple Machines Forum (SMF) versions 2.x prior to 2.0 RC5, update to version 2.0 RC5 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1130

Affected Products

Simple Machines Forum