Simple Machines Forum (SMF) <= 2.0.5 multiple vulnerabilities

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044592 漏洞类型
发布时间 2013-08-15 更新时间 2013-08-15
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013080129
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
According to

http://simplemachines.org/community/?topic=509417#msg3592194

Simple Machines Forum <= 2.0.5 (but > 1.1.*) is vulnerable to one or
more (currently undocumented) security issues.

The changes between v2.0.4 and 2.0.5 can be reviewed at
http://custom.simplemachines.org/upgrades/index.php?action=upgrade;file=smf_patch_2.0.5.tar.gz;smf_version=2.0.4

This is just a heads up, I haven't tried to look into those in detail.

CVE folks: If you'll handle this, please also check the last ones:
http://simplemachines.org/community/?topic=496403.0
http://osvdb.org/show/osvdb/92745
http://osvdb.org/show/osvdb/88909

Moritz
-- 
Naumann IT Security Consulting

Samariterstr. 16
10247 Berlin
Germany