Page 3 of 34 results (0.006 seconds)

CVSS: 4.3EPSS: 0%CPEs: 71EXPL: 0

Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header. Simple Machines Forum (SMF) anterior a 1.1.19 y 2.x anterior a 2.0.6 permite a atacantes remotos realizar ataques de clickjacking a través de una cabecera X-Frame-Options. • http://download.simplemachines.org/index.php?thanks%3Bfilename=smf_2-0-6_changelog.txt http://seclists.org/fulldisclosure/2013/Dec/83 http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software http://www.openwall.com/lists/oss-security/2013/12/30/1 http://www.openwall.com/lists/oss-security/2013/12/30/3 • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 0%CPEs: 55EXPL: 0

Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username. Simple Machines Forum (SMF) 2.0.6, 1.1.19, y anteriores permite a atacantes remotos suplantar usuarios arbitrarios a través de un carácter Unicode homógrafos en un nombre de usuario. • http://seclists.org/fulldisclosure/2013/Dec/83 http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software http://www.openwall.com/lists/oss-security/2013/12/30/1 http://www.openwall.com/lists/oss-security/2013/12/30/3 • CWE-20: Improper Input Validation •

CVSS: 4.6EPSS: 0%CPEs: 48EXPL: 0

Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. vulnerabilidad de subida sin restricción de archivos en la funcionalidad avatar upload en Simple Machines Forum antes de 2.0.6 y 2.1 que permite a los usuarios remotos autenticados ejecutar código arbitrario mediante la carga de un archivo con una extensión ejecutable , y a continuación, acceder a él a través de una petición directa al archivo en un directorio no especificado . • http://download.simplemachines.org/index.php?thanks%3Bfilename=smf_2-0-6_changelog.txt http://www.openwall.com/lists/oss-security/2013/10/23/6 http://www.openwall.com/lists/oss-security/2013/10/25/3 http://www.securityfocus.com/bid/63275 https://github.com/SimpleMachines/SMF2.1/issues/701 •

CVSS: 7.5EPSS: 0%CPEs: 12EXPL: 2

SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "\" (backslash) sequence that does not quote the "'" (single quote) character, as demonstrated via a manlabels action to index.php. Vulnerabilidad de inyección SQL en Load.php en Simple Machines Forum (SMF) v1.1.4 y anteriores permite a atacantes remotos ejecutar comandos SQL de forma arbitraria mediante el ajuste de el parámetro "db_character_set" a caracteres multibyte tal como big5, lo que produce que la función de PHP "addslashes" produzca una secuencia "\" (barra invertida) no la comilla "'" (comilla simple), como se demostró a través de la acción "manlabels" en index.php. • https://www.exploit-db.com/exploits/5826 http://www.securityfocus.com/bid/29734 https://exchange.xforce.ibmcloud.com/vulnerabilities/43118 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.8EPSS: 0%CPEs: 14EXPL: 2

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en index.php en Simple Machines Forum (SMF) v1.0 anteriores a v1.0.15 y v1.1 anteriores a v1.1.7 permite a atacantes remotos secuestrar la autenticación de los administradores para realizar peticiones para instalar paquetes a través del parámetro "package" en una acción install2. • https://www.exploit-db.com/exploits/6993 http://osvdb.org/50071 http://secunia.com/advisories/32516 http://www.securityfocus.com/bid/32119 http://www.simplemachines.org/community/index.php?topic=272861.0 https://exchange.xforce.ibmcloud.com/vulnerabilities/46343 • CWE-352: Cross-Site Request Forgery (CSRF) •