PT-2020-7038 · Unknown · Simple Machines Forum
Henri Salo
·
Published
2020-01-15
·
Updated
2020-01-21
·
CVE-2005-4891
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machine Forum (SMF) versions 1.0.4 and earlier
Description
The issue allows remote attackers to inject arbitrary SQL statements, which is a type of SQL injection vulnerability. This means an attacker can execute unauthorized SQL code on the database, potentially leading to data manipulation or extraction.
Recommendations
For Simple Machine Forum (SMF) versions 1.0.4 and earlier, update to a version later than 1.0.4 to resolve the SQL injection vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Machines Forum