Korean
<< Back
VID 21750
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Simple Machines Forum, according to its version number, has an information disclosure vulnerability. Simple Machines Forum (SMF) is an open-source web forum application written in PHP. SMF version 1.0.5 and earlier versions could allow a remote attacker to obtain sensitive information. A remote authenticated attacker can set their avatar image filename to a URL for a remote PHP script. When a target user views an SMF page that ostensibly contains the avatar picture, the target user's browser will load the URL. As a result, the remote script can obtain information about the target user, such as IP address and HTTP header parameters.

* Note: This check solely relied on the version number of Simple Machines Forum installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://rgod.altervista.org/smf105.html
http://www.securitytracker.com/alerts/2005/Aug/1014828.html

* Platforms Affected:
Simple Machines, SMF version 1.0.5 and earlier versions
Any operating system Any version
Recommendation Upgrade to the latest version of Simple Machines Forum (1.1 RC1 or later), available from the Simple Machines Download Web site at http://www.simplemachines.org/download.php
Related URL CVE-2005-2817 (CVE)
Related URL (SecurityFocus)
Related URL 22093 (ISS)