Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities
BID:50103
Info
Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities
| Bugtraq ID: | 50103 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3615 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2011 12:00AM |
| Updated: | Oct 13 2011 12:00AM |
| Credit: | Simple Machines |
| Vulnerable: |
Simple Machines Simple Machines Forum 1.1.13 Simple Machines Simple Machines Forum 1.1.12 Simple Machines Simple Machines Forum 1.1.11 Simple Machines Simple Machines Forum 1.1.10 Simple Machines Simple Machines Forum 1.1.9 Simple Machines Simple Machines Forum 1.1.8 Simple Machines Simple Machines Forum 1.1.7 Simple Machines Simple Machines Forum 1.1.6 Simple Machines Simple Machines Forum 1.1.5 Simple Machines Simple Machines Forum 1.1.4 Simple Machines Simple Machines Forum 1.1.3 Simple Machines Simple Machines Forum 1.1.2 Simple Machines Simple Machines Forum 1.1.1 Simple Machines Simple Machines Forum 1.0.16 Simple Machines Simple Machines Forum 1.0.14 Simple Machines Simple Machines Forum 2.0.RC5 Simple Machines Simple Machines Forum 2.0 RC2 Simple Machines Simple Machines Forum 2.0 RC1-1 Simple Machines Simple Machines Forum 2.0 RC1 Simple Machines Simple Machines Forum 2.0 Simple Machines Simple Machines Forum 1.1.14 |
| Not Vulnerable: |
Simple Machines Simple Machines Forum 2.0.1 Simple Machines Simple Machines Forum 1.1.15 |
Discussion
Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities
Simple Machines Forum is prone to a cross-site scripting vulnerability and a vulnerability that may aid in phishing attacks.
An attacker may leverage these issues to mislead a user to believe that they are viewing a legitimate site, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or steal cookie-based authentication credentials. Other attacks are also possible.
Simple Machines Forum 1.x prior to 1.1.15 and 2.x prior to 2.0.1 are vulnerable.
Simple Machines Forum is prone to a cross-site scripting vulnerability and a vulnerability that may aid in phishing attacks.
An attacker may leverage these issues to mislead a user to believe that they are viewing a legitimate site, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or steal cookie-based authentication credentials. Other attacks are also possible.
Simple Machines Forum 1.x prior to 1.1.15 and 2.x prior to 2.0.1 are vulnerable.
Exploit / POC
Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Simple Machines Forum Cross-Site Scripting and Spoofing Vulnerabilities
References:
References:
- Simple Machines Homepage (Simple Machines)
- SMF 2.0.1 and 1.1.15 critical security patches released (Simple Machines)