News:

Want to get involved in developing SMF? Why not lend a hand on our GitHub!

Main Menu

Simple Machines Forum Memberlist.php SQL Injection Vulnerability

Started by DomDom Skye, December 12, 2005, 02:37:53 AM

Previous topic - Next topic

DomDom Skye

Hello

I discover this:
QuoteSimple Machines Forum is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. A successful attack can allow an attacker to bypass administrator login and gain administrative access to a site.

Simple Machines Forum 1.1 rc1 is vulnerable. Other versions may also be affected.

http://www.securityfocus.com/bid/15791/exploit

Any patch?

Regards, Dom



DomDom Skye


Advertisement: