CVE-2006-4467
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read arbitrary local files, lock topics, and possibly have other security impacts. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Simple Machines Forum.
Simple Machines Forum (SMF) 1.1RCx anterior a 1.1RC3, y 1.0.x anterior a 1.0.8, no asigna correctamente variables cuando los datos de entrada incluyen un parámetro numérico con un valor que empareja el valor del hash de un parámetro alfanumérico, lo cual permite a un atacante remoto llevar a cabo ataques de directorio transversal para leer archivos locales de su elección, bloquear asuntos, y tener posiblemente otros impactos de seguridad. NOTA: podría ser discutido que esta vulnerabilidad es debida a un fallo en el comando unset de PHP (CVE-2006-3017) y la solución apropiada debe estar en el PHP; si es así entonces esto no se debe tratar como vulnerabilidad en Simple Machines Forum.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-08-31 CVE Reserved
- 2006-08-31 CVE Published
- 2023-08-12 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://retrogod.altervista.org/smf_11rc2_local_incl.html | X_refsource_misc | |
http://retrogod.altervista.org/smf_11rc2_lock.html | X_refsource_misc | |
http://securityreason.com/securityalert/1475 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/444053/100/100/threaded | Mailing List | |
http://www.simplemachines.org/community/index.php?topic=107112.0 | X_refsource_confirm | |
http://www.simplemachines.org/community/index.php?topic=107135.0 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simple Machines Search vendor "Simple Machines" | Simple Machines Forum Search vendor "Simple Machines" for product "Simple Machines Forum" | <= 1.0.7 Search vendor "Simple Machines" for product "Simple Machines Forum" and version " <= 1.0.7" | - |
Affected
| ||||||
Simple Machines Search vendor "Simple Machines" | Simple Machines Forum Search vendor "Simple Machines" for product "Simple Machines Forum" | <= 1.1_rc2 Search vendor "Simple Machines" for product "Simple Machines Forum" and version " <= 1.1_rc2" | - |
Affected
|