Lucene search

K
cveMitreCVE-2008-6657
HistoryApr 07, 2009 - 7:30 p.m.

CVE-2008-6657

2009-04-0719:30:00
CWE-352
mitre
web.nvd.nist.gov
33
csrf
vulnerability
simple machines forum
smf
authentication
admin hijacking

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.007

Percentile

80.5%

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

Affected configurations

Nvd
Node
simple_machinessimple_machines_forumMatch1.0.5
OR
simple_machinessimple_machines_forumMatch1.0.6
OR
simple_machinessimple_machines_forumMatch1.0.7
OR
simple_machinessimple_machines_forumMatch1.0.11
OR
simple_machinessimple_machines_forumMatch1.0.12
OR
simple_machinessimple_machines_forumMatch1.1.1
OR
simple_machinessimple_machines_forumMatch1.1.2
OR
simple_machinessimple_machines_forumMatch1.1.3
OR
simple_machinessimple_machines_forumMatch1.1.4
OR
simple_machinessimple_machines_forumMatch1.1.5
OR
simple_machinessimple_machines_forumMatch1.1.6
OR
simple_machinessimple_machines_forumMatch1.1_rc1
OR
simple_machinessimple_machines_forumMatch1.1_rc2
OR
simple_machinessimple_machines_forumMatch1.1_rc3
VendorProductVersionCPE
simple_machinessimple_machines_forum1.0.5cpe:2.3:a:simple_machines:simple_machines_forum:1.0.5:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.0.6cpe:2.3:a:simple_machines:simple_machines_forum:1.0.6:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.0.7cpe:2.3:a:simple_machines:simple_machines_forum:1.0.7:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.0.11cpe:2.3:a:simple_machines:simple_machines_forum:1.0.11:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.0.12cpe:2.3:a:simple_machines:simple_machines_forum:1.0.12:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.1.1cpe:2.3:a:simple_machines:simple_machines_forum:1.1.1:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.1.2cpe:2.3:a:simple_machines:simple_machines_forum:1.1.2:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.1.3cpe:2.3:a:simple_machines:simple_machines_forum:1.1.3:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.1.4cpe:2.3:a:simple_machines:simple_machines_forum:1.1.4:*:*:*:*:*:*:*
simple_machinessimple_machines_forum1.1.5cpe:2.3:a:simple_machines:simple_machines_forum:1.1.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.007

Percentile

80.5%

Related for CVE-2008-6657