Simple Machines Forum Multiple Security Vulnerabilities
18 Jul. 2012
Summary
Simple Machines Forum is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input. These vulnerabilities include a security-bypass vulnerability, a cross-site scripting vulnerability, an SQL-injection vulnerability, a denial-of service vulnerability, and multiple information-disclosure vulnerabilities.
Vulnerable Systems:
*Simple Machines Simple Machines Forum 1.1.12 and prior
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, exploit latent vulnerabilities in the underlying database, deny service to legitimate users, or perform unauthorized actions. Other attacks are also possible.
Simple Machines Forum versions prior to 1.1.13 and 2.x before 2.0 RC5 are vulnerable.
Vendor Status:
Vendor as issued an updated vulnerability.