Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simple Machines Forum HIGH 7.5
CVE-2008-6741

SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by…

Fix: after 1.1.4
Fix from $1,950 2009-04-21
Simple Machines Forum MEDIUM 6.8
CVE-2008-6657

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote atta…

No fix yet
Fix from $1,600 2009-04-07
Simple Machines Forum MEDIUM 5.5
CVE-2008-6659

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated user…

No fix yet
Fix from $1,600 2009-04-07
Simple Machines Forum HIGH 7.5
CVE-2008-6544

Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2009-03-30
Simple Machines Forum HIGH 7.5
CVE-2008-3072

Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number ge…

Fix: after 1.1.4
Fix from $1,950 2008-07-08
Simple Machines Forum HIGH 7.5
CVE-2008-3073

Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors, probably c…

Fix: after 1.1.4
Fix from $1,950 2008-07-08
Smf HIGH 7.5
CVE-2008-2019

Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA,…

Mitigation only
Fix from $1,950 2008-04-30
Simple Machines Forum MEDIUM 5.0
CVE-2007-5943

Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show resu…

Mitigation only
Fix from $1,600 2007-11-14
Simple Machines Forum MEDIUM 6.8
CVE-2007-5646

SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbi…

Patch available
Fix from $1,600 2007-10-23
Simple Machines Forum MEDIUM 5.8
CVE-2007-3942

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified ve…

Mitigation only
Fix from $1,600 2007-07-21
Simple Machines Forum HIGH 7.5
CVE-2007-3308

Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote a…

Mitigation only
Fix from $1,950 2007-06-21
Simple Machines Forum HIGH 7.5
CVE-2007-3309

Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editi…

Mitigation only
Fix from $1,950 2007-06-21
Simple Machines Forum MEDIUM 6.8
CVE-2007-2546

Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESS…

Fix: after 1.1.2
Fix from $1,600 2007-05-09
Simple Machines Forum HIGH 7.5
CVE-2006-7013

QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address…

Fix: after 1.1_rc2
Fix from $1,950 2007-02-15
Simple Machines Forum MEDIUM 6.0
CVE-2007-0399

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject ar…

Mitigation only
Fix from $1,600 2007-01-22
Smf MEDIUM 6.8
CVE-2006-6375

Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitr…

Patch available
Fix from $1,600 2006-12-07
Simple Machines Forum HIGH 7.5
CVE-2006-4467

Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric pa…

Fix: after 1.1_rc2
Fix from $1,950 2006-08-31
Simple Machines Forum HIGH 7.5
CVE-2005-4159

NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 …

Fix: after 1.1_rc1
Fix from $1,950 2005-12-11
Simple Machines Forum MEDIUM 5.0
CVE-2005-2817

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive informat…

No fix yet
Fix from $1,600 2005-09-07