LoveCMS Simple Forum Password Reset Security Bypass Vulnerability
BID:32435
Info
LoveCMS Simple Forum Password Reset Security Bypass Vulnerability
| Bugtraq ID: | 32435 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-5308 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | cOndemned |
| Vulnerable: |
LoveCMS Simple Forum 3.1d LoveCMS LoveCMS 1.6.2 |
| Not Vulnerable: | |
Discussion
LoveCMS Simple Forum Password Reset Security Bypass Vulnerability
Simple Forum is prone to a security-bypass.
Exploiting this issue may allow attackers to compromise the application; other attacks are also possible.
Simple Forum 3.1d is vulnerable; other versions may also be affected.
Simple Forum is prone to a security-bypass.
Exploiting this issue may allow attackers to compromise the application; other attacks are also possible.
Simple Forum 3.1d is vulnerable; other versions may also be affected.
Exploit / POC
LoveCMS Simple Forum Password Reset Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit code is available:
Attackers can exploit this issue via a browser.
The following exploit code is available:
Solution / Fix
LoveCMS Simple Forum Password Reset Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
LoveCMS Simple Forum Password Reset Security Bypass Vulnerability
References:
References:
- Simple Forum Download page (LoveCMS)