Simple Machines Msg Parameter SQL Injection Vulnerability
BID:14043
Info
Simple Machines Msg Parameter SQL Injection Vulnerability
| Bugtraq ID: | 14043 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2005 12:00AM |
| Updated: | Jun 23 2005 12:00AM |
| Credit: | Discovery of this vulnerability is credited to James. |
| Vulnerable: |
Simple Machines SMF 1.0.4 Simple Machines SMF 1.0.2 Simple Machines SMF 1.0 -beta5p Simple Machines SMF 1.0 -beta4p Simple Machines SMF 1.0 -beta4.1 |
| Not Vulnerable: |
Simple Machines SMF 1.0.5 |
Discussion
Simple Machines Msg Parameter SQL Injection Vulnerability
Simple Machines is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
This issue is reported to affect Simple Machines version 1.0.4; earlier versions may also be vulnerable.
Simple Machines is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
This issue is reported to affect Simple Machines version 1.0.4; earlier versions may also be vulnerable.
Exploit / POC
Simple Machines Msg Parameter SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Simple Machines Msg Parameter SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in Simple Machines version 1.0.5 and later:
Simple Machines SMF 1.0 -beta4.1
Simple Machines SMF 1.0 -beta4p
Simple Machines SMF 1.0 -beta5p
Simple Machines SMF 1.0.2
Simple Machines SMF 1.0.4
Solution:
The vendor has addressed this issue in Simple Machines version 1.0.5 and later:
Simple Machines SMF 1.0 -beta4.1
-
Simple Machines smf_1-0-5_install.zip
http://www.simplemachines.org/download.php/smf_1-0-5_install.zip
Simple Machines SMF 1.0 -beta4p
-
Simple Machines smf_1-0-5_install.zip
http://www.simplemachines.org/download.php/smf_1-0-5_install.zip
Simple Machines SMF 1.0 -beta5p
-
Simple Machines smf_1-0-5_install.zip
http://www.simplemachines.org/download.php/smf_1-0-5_install.zip
Simple Machines SMF 1.0.2
-
Simple Machines smf_1-0-5_install.zip
http://www.simplemachines.org/download.php/smf_1-0-5_install.zip
Simple Machines SMF 1.0.4
-
Simple Machines smf_1-0-5_install.zip
http://www.simplemachines.org/download.php/smf_1-0-5_install.zip
References
Simple Machines Msg Parameter SQL Injection Vulnerability
References:
References:
- Simple Machines SMF Homepage (Simple Machines)
- SMF Community Forum (Simple Machines)