Show filters
38 Total Results
Displaying 11-20 of 38
Sort by:
Attacker Value
Unknown
CVE-2018-10305
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2016-5727
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
0
Attacker Value
Unknown
CVE-2016-5726
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
0
Attacker Value
Unknown
CVE-2013-7235
Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters.
0
Attacker Value
Unknown
CVE-2013-7236
Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
0
Attacker Value
Unknown
CVE-2013-7234
Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
0
Attacker Value
Unknown
CVE-2013-4465
Disclosure Date: October 25, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
0
Attacker Value
Unknown
CVE-2008-6741
Disclosure Date: April 21, 2009 (last updated October 04, 2023)
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "\" (backslash) sequence that does not quote the "'" (single quote) character, as demonstrated via a manlabels action to index.php.
0
Attacker Value
Unknown
CVE-2008-6659
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to Sources/QueryString.php and Sources/Themes.php, as demonstrated by a local .gif file in attachments/ with PHP code that was uploaded through a profile2 action to index.php.
0
Attacker Value
Unknown
CVE-2008-6658
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.
0