|
|
| |
| Simple Machines Forum is prone to an information-disclosure vulnerability because it includes session credentials in the URL in certain circumstances. |
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/49078
|
| |
Vulnerable Systems:
* Simple Machines Simple Machines Forum 2.0
An attacker can exploit this issue to gain access to valid session credentials; this may aid in further attacks.
Simple Machines Forum 2.0 is vulnerable; other versions may also be affected.
Vendor Status:
Simple Machines as issued an update for this vulnerablity
Patch Availability:
http://download.simplemachines.org/
Disclosure Timeline:
Initial Release Aug 07 2011
|
|
blog comments powered by
|