Simple Machines Forum Password Reset Security Bypass Vulnerability
BID:33219
Info
Simple Machines Forum Password Reset Security Bypass Vulnerability
| Bugtraq ID: | 33219 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2009 12:00AM |
| Updated: | Feb 09 2009 05:28PM |
| Credit: | Xianur0 |
| Vulnerable: |
Simple Machines SMF 1.1.5 Simple Machines SMF 1.1.5 Simple Machines SMF 1.1.4 Simple Machines SMF 1.1.3 Simple Machines SMF 1.1.2 Simple Machines SMF 1.1.1 Simple Machines SMF 1.1 rc3 Simple Machines SMF 1.1 rc3 Simple Machines SMF 1.1 rc2 Simple Machines SMF 1.1 rc1 Simple Machines SMF 1.1 final Simple Machines SMF 1.0.13 Simple Machines SMF 1.0.13 Simple Machines SMF 1.0.12 Simple Machines SMF 1.0.12 Simple Machines SMF 1.0.11 Simple Machines SMF 1.0.10 Simple Machines SMF 1.0.9 Simple Machines SMF 1.0.8 Simple Machines SMF 1.0.8 Simple Machines SMF 1.0.7 Simple Machines SMF 1.0.6 Simple Machines SMF 1.0.5 Simple Machines SMF 1.0.4 Simple Machines SMF 1.0.3 Simple Machines SMF 1.0.2 Simple Machines SMF 1.0.1 Simple Machines SMF 1.0 -beta5p Simple Machines SMF 1.0 -beta4p Simple Machines SMF 1.0 -beta4.1 Simple Machines Simple Machines Forum 1.1.5 Simple Machines Simple Machines Forum 1.1.4 Simple Machines Simple Machines Forum 1.1.3 Simple Machines Simple Machines Forum 1.1.2 Simple Machines Simple Machines Forum 1.1.1 |
| Not Vulnerable: |
Simple Machines Simple Machines Forum 1.1.6 Simple Machines Simple Machines Forum 1.0.14 |
Discussion
Simple Machines Forum Password Reset Security Bypass Vulnerability
Simple Machines Forum is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-reset feature.
An attacker can exploit this issue to gain administrative access to the application, which may allow the attacker to compromise the application; other attacks are also possible.
Versions up to and including Simple Machines Forum 1.1.7 are vulnerable.
UPDATE (February 6, 2009): The vendor indicates that this issue was resolved in Simple Machines Forum 1.0.14 and 1.1.6.
Simple Machines Forum is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-reset feature.
An attacker can exploit this issue to gain administrative access to the application, which may allow the attacker to compromise the application; other attacks are also possible.
Versions up to and including Simple Machines Forum 1.1.7 are vulnerable.
UPDATE (February 6, 2009): The vendor indicates that this issue was resolved in Simple Machines Forum 1.0.14 and 1.1.6.
Exploit / POC
Simple Machines Forum Password Reset Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit code is available:
Attackers can exploit this issue via a browser.
The following exploit code is available:
Solution / Fix
Simple Machines Forum Password Reset Security Bypass Vulnerability
Solution:
The vendor indicates that this issue was addressed in SMF 1.0.14 and 1.1.6. Please see the references for more information.
Solution:
The vendor indicates that this issue was addressed in SMF 1.0.14 and 1.1.6. Please see the references for more information.
References
Simple Machines Forum Password Reset Security Bypass Vulnerability
References:
References:
- Bug en smf? (Montana)
- Simple Machines Homepage (Simple Machines)