Skip to main content

Vendor/product archive

simplemachines / smf CVEs

Beta · best-effort

9 CVEs tagged to simplemachines / smf1 Critical, 4 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2011-4173

Published Oct 24, 2011

Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication of administrators or moderator…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3615

Published Oct 24, 2011

Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors invol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1131

Published Jun 21, 2011

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1130

Published Jun 21, 2011

Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1129

Published Jun 21, 2011

Cross-site scripting (XSS) vulnerability in the EditNews function in ManageNews.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, might allow remote authen…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1128

Published Jun 21, 2011

The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1127

Published Jun 21, 2011

SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6971

Published Aug 13, 2009

The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4564

Published Sep 6, 2006

SQL injection vulnerability in Sources/ManageBoards.php in Simple Machines Forum 1.1 RC3 allows remote attackers to execute arbitrary SQL commands via the cur_cat parameter.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1