PT-2011-2894 · Simple Machines · Simple Machines Forum
Steven M. Christey
·
Published
2011-06-21
·
Updated
2012-12-20
·
CVE-2011-1130
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machines Forum (SMF) versions prior to 1.1.13
Simple Machines Forum (SMF) versions 2.x prior to 2.0 RC5
Description
The issue is related to improper validation of the
start parameter, which could allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value. This is related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.Recommendations
For Simple Machines Forum (SMF) versions prior to 1.1.13, update to version 1.1.13 or later.
For Simple Machines Forum (SMF) versions 2.x prior to 2.0 RC5, update to version 2.0 RC5 or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Machines Forum