CVE-2011-1130
- EPSS 1.08%
- Veröffentlicht 21.06.2011 02:52:42
- Zuletzt bearbeitet 16.06.2026 23:28:46
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a c...
- EPSS 1.24%
- Veröffentlicht 21.06.2011 02:52:42
- Zuletzt bearbeitet 16.06.2026 23:28:46
The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situatio...
CVE-2008-6971
- EPSS 7.13%
- Veröffentlicht 13.08.2009 16:30:01
- Zuletzt bearbeitet 16.06.2026 23:03:20
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation ...
CVE-2006-4564
- EPSS 1.07%
- Veröffentlicht 06.09.2006 01:04:00
- Zuletzt bearbeitet 16.06.2026 22:29:20
SQL injection vulnerability in Sources/ManageBoards.php in Simple Machines Forum 1.1 RC3 allows remote attackers to execute arbitrary SQL commands via the cur_cat parameter.