|
|
|
|
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/16841
The information has been provided by Aliaksandr Hartsuyeu.
|
| |
Vulnerable Systems:
* Simple Machines SMF 1.0.6
* Simple Machines SMF 1.0.5
* Simple Machines SMF 1.0.4
* Simple Machines SMF 1.0.2
* Simple Machines SMF 1.0 -beta5p
* Simple Machines SMF 1.0 -beta4p
* Simple Machines SMF 1.0 -beta4.1
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect Simple Machines version 1.0.6 and earlier.
Vendor Status:
Simple Machines as issued an update for this vulnerablity
Patch Availability:
http://download.simplemachines.org/
CVE Information:
CVE-2006-0896
Disclosure Timeline:
Initial Release Feb 24 2006
|
|
|
|
|