VID |
21749 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Simple Machines Forum, according to its version number, has an SQL injection vulnerability via the msg parameter. Simple Machines Forum (SMF) is an open-source web forum application written in PHP. SMF version 1.0.4 and earlier versions could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'msg' parameter. This vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.
* Note: This check solely relied on the version number of Simple Machines Forum installed on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/15784/ http://www.gulftech.org/?node=research&article_id=00089-07032005
* Platforms Affected: Simple Machines, SMF version 1.0.4 and earlier versions Any operating system Any version |
Recommendation |
Upgrade to the latest version of Simple Machines Forum (1.0.5 or later), available from the Simple Machines Download Web site at http://www.simplemachines.org/download.php |
Related URL |
(CVE) |
Related URL |
14043 (SecurityFocus) |
Related URL |
(ISS) |
|