CVE-2013-7468
https://notcve.org/view.php?id=CVE-2013-7468
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter. Simple Machines Forum (SMF), en su versión 2.0.4, permite la inyección de código PHP mediante el parámetro dictionary en index.php?action=admin;area=languages;sa=editlang. • https://packetstormsecurity.com/files/121391/public_phpInjection-smf204.txt • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2018-10305
https://notcve.org/view.php?id=CVE-2018-10305
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions. La función MessageSearch2 en PersonalMessage.php en Simple Machines Forum (SMF), en versiones anteriores a la 2.0.15, no emplea correctamente la variable possible_users en una consulta, lo que podría permitir que los atacantes omitan las restricciones de acceso planeadas. • https://www.simplemachines.org/community/index.php?topic=557176.0 •
CVE-2013-7235
https://notcve.org/view.php?id=CVE-2013-7235
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters. Simple Machines Forum (SMF) anterior a 1.1.19 y 2.x anterior a 2.0.6 permite a atacantes remotos suplantar usuarios arbitrarios a través de múltiples caracteres de espacio. • http://download.simplemachines.org/index.php?thanks%3Bfilename=smf_2-0-6_changelog.txt http://seclists.org/fulldisclosure/2013/Dec/83 http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software http://www.openwall.com/lists/oss-security/2013/12/30/1 http://www.openwall.com/lists/oss-security/2013/12/30/3 • CWE-20: Improper Input Validation •
CVE-2013-7234
https://notcve.org/view.php?id=CVE-2013-7234
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header. Simple Machines Forum (SMF) anterior a 1.1.19 y 2.x anterior a 2.0.6 permite a atacantes remotos realizar ataques de clickjacking a través de una cabecera X-Frame-Options. • http://download.simplemachines.org/index.php?thanks%3Bfilename=smf_2-0-6_changelog.txt http://seclists.org/fulldisclosure/2013/Dec/83 http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software http://www.openwall.com/lists/oss-security/2013/12/30/1 http://www.openwall.com/lists/oss-security/2013/12/30/3 • CWE-20: Improper Input Validation •
CVE-2013-7236
https://notcve.org/view.php?id=CVE-2013-7236
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username. Simple Machines Forum (SMF) 2.0.6, 1.1.19, y anteriores permite a atacantes remotos suplantar usuarios arbitrarios a través de un carácter Unicode homógrafos en un nombre de usuario. • http://seclists.org/fulldisclosure/2013/Dec/83 http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software http://www.openwall.com/lists/oss-security/2013/12/30/1 http://www.openwall.com/lists/oss-security/2013/12/30/3 • CWE-20: Improper Input Validation •