// For flags

CVE-2011-1131

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situations where a temporary table has not been created, which might allow remote attackers to obtain sensitive information via a search.

La función PlushSearch2 en Search.php de Simple Machines Forum (SMF)antes de v1.1.13 y v2.x antes de v2.0 RC5, usa ciertos datos almacenados en caché en una situación en la que ha sido creada una tabla temporal , a pesar de estos datos en caché solo se usan en situaciones en las que una tabla temporal no se ha creado, lo que podría permitir a atacantes remotos obtener información sensible a través de una búsqueda.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-03-02 CVE Reserved
  • 2011-06-21 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
<= 1.1.12
Search vendor "Simplemachines" for product "Smf" and version " <= 1.1.12"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
beta4
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
beta4.1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
beta5
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
beta6
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
rc1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0
Search vendor "Simplemachines" for product "Smf" and version "1.0"
rc2
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.1
Search vendor "Simplemachines" for product "Smf" and version "1.0.1"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.2
Search vendor "Simplemachines" for product "Smf" and version "1.0.2"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.3
Search vendor "Simplemachines" for product "Smf" and version "1.0.3"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.4
Search vendor "Simplemachines" for product "Smf" and version "1.0.4"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.5
Search vendor "Simplemachines" for product "Smf" and version "1.0.5"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.6
Search vendor "Simplemachines" for product "Smf" and version "1.0.6"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.7
Search vendor "Simplemachines" for product "Smf" and version "1.0.7"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.8
Search vendor "Simplemachines" for product "Smf" and version "1.0.8"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.9
Search vendor "Simplemachines" for product "Smf" and version "1.0.9"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.10
Search vendor "Simplemachines" for product "Smf" and version "1.0.10"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.12
Search vendor "Simplemachines" for product "Smf" and version "1.0.12"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.13
Search vendor "Simplemachines" for product "Smf" and version "1.0.13"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.14
Search vendor "Simplemachines" for product "Smf" and version "1.0.14"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.15
Search vendor "Simplemachines" for product "Smf" and version "1.0.15"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.16
Search vendor "Simplemachines" for product "Smf" and version "1.0.16"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.17
Search vendor "Simplemachines" for product "Smf" and version "1.0.17"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.18
Search vendor "Simplemachines" for product "Smf" and version "1.0.18"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.19
Search vendor "Simplemachines" for product "Smf" and version "1.0.19"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.20
Search vendor "Simplemachines" for product "Smf" and version "1.0.20"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.0.21
Search vendor "Simplemachines" for product "Smf" and version "1.0.21"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
beta1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
beta2
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
beta3
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
beta4
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
rc1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
rc2
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1"
rc3
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.1
Search vendor "Simplemachines" for product "Smf" and version "1.1.1"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.2
Search vendor "Simplemachines" for product "Smf" and version "1.1.2"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.3
Search vendor "Simplemachines" for product "Smf" and version "1.1.3"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.4
Search vendor "Simplemachines" for product "Smf" and version "1.1.4"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.5
Search vendor "Simplemachines" for product "Smf" and version "1.1.5"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.6
Search vendor "Simplemachines" for product "Smf" and version "1.1.6"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.7
Search vendor "Simplemachines" for product "Smf" and version "1.1.7"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.8
Search vendor "Simplemachines" for product "Smf" and version "1.1.8"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.9
Search vendor "Simplemachines" for product "Smf" and version "1.1.9"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.10
Search vendor "Simplemachines" for product "Smf" and version "1.1.10"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
1.1.11
Search vendor "Simplemachines" for product "Smf" and version "1.1.11"
-
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
beta1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
beta2
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
beta2.1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
beta3
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
beta3.1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
beta4
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
rc1
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
rc2
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
rc3
Affected
Simplemachines
Search vendor "Simplemachines"
Smf
Search vendor "Simplemachines" for product "Smf"
2.0
Search vendor "Simplemachines" for product "Smf" and version "2.0"
rc4
Affected