Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown

CVE-2008-6657

Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.
0
Attacker Value
Unknown

CVE-2008-6544

Disclosure Date: March 30, 2009 (last updated November 08, 2023)
Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter to Sources/Themes.php. NOTE: CVE and multiple third parties dispute this issue because the files contain a protection mechanism against direct request
0
Attacker Value
Unknown

CVE-2008-3073

Disclosure Date: July 08, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors, probably cross-site scripting (XSS), related to "use of the html-tag."
0
Attacker Value
Unknown

CVE-2008-3072

Disclosure Date: July 08, 2008 (last updated October 04, 2023)
Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2007-5943

Disclosure Date: November 14, 2007 (last updated October 04, 2023)
Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message.
0
Attacker Value
Unknown

CVE-2007-5646

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
0
Attacker Value
Unknown

CVE-2007-3942

Disclosure Date: July 21, 2007 (last updated November 08, 2023)
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray are defined before use
0
Attacker Value
Unknown

CVE-2007-3308

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack.
0
Attacker Value
Unknown

CVE-2007-3309

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.
0
Attacker Value
Unknown

CVE-2007-2546

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
0