Advertisement






Simple Machines Forum <=1.1RC2 unset() vulnerabilities

CVE Category Price Severity
CVE-2007-4001 CWE-79 $300 High
Author Risk Exploitation Type Date
I0p0 High Remote 2006-09-05
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006090003

Below is a copy:

---------Simple Machines Forum <=1.1RC2 unset() vulnerabilities-----------------

------------------------------------------------------------------------
--------

software site: http://www.simplemachines.org/

the recently discovered Zend_Hash_Del_Key_Or_Index PHP vulnerability allows

users to include arbitrary files from local resources (on Windows boxes)

and to lock topics, poc for both:

http://retrogod.altervista.org/smf_11rc2_local_incl.html

http://retrogod.altervista.org/smf_11rc2_lock.html

an interesting reading:

http://www.hardened-php.net/hphp/zend_hash_del_key_or_index_vulnerabilit
y.html

SMF team released 1.0.8 and 1.1.rc3 versions to patch theese issues

------------------------------------------------------------------------
--------

rgod

site: http://retrogod.altervista.org

mail: rgod at autistici.org

------------------------------------------------------------------------
--------

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum