Lucene search

K
cveMitreCVE-2011-1131
HistoryJun 21, 2011 - 2:52 a.m.

CVE-2011-1131

2011-06-2102:52:42
CWE-200
mitre
web.nvd.nist.gov
20
cve-2011-1131
simple machines forum
smf
plushsearch2
search.php
information disclosure

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

73.1%

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situations where a temporary table has not been created, which might allow remote attackers to obtain sensitive information via a search.

Affected configurations

Nvd
Node
simplemachinessmfRange1.1.12
OR
simplemachinessmfMatch1.0
OR
simplemachinessmfMatch1.0beta4
OR
simplemachinessmfMatch1.0beta4.1
OR
simplemachinessmfMatch1.0beta5
OR
simplemachinessmfMatch1.0beta6
OR
simplemachinessmfMatch1.0rc1
OR
simplemachinessmfMatch1.0rc2
OR
simplemachinessmfMatch1.0.1
OR
simplemachinessmfMatch1.0.2
OR
simplemachinessmfMatch1.0.3
OR
simplemachinessmfMatch1.0.4
OR
simplemachinessmfMatch1.0.5
OR
simplemachinessmfMatch1.0.6
OR
simplemachinessmfMatch1.0.7
OR
simplemachinessmfMatch1.0.8
OR
simplemachinessmfMatch1.0.9
OR
simplemachinessmfMatch1.0.10
OR
simplemachinessmfMatch1.0.12
OR
simplemachinessmfMatch1.0.13
OR
simplemachinessmfMatch1.0.14
OR
simplemachinessmfMatch1.0.15
OR
simplemachinessmfMatch1.0.16
OR
simplemachinessmfMatch1.0.17
OR
simplemachinessmfMatch1.0.18
OR
simplemachinessmfMatch1.0.19
OR
simplemachinessmfMatch1.0.20
OR
simplemachinessmfMatch1.0.21
OR
simplemachinessmfMatch1.1
OR
simplemachinessmfMatch1.1beta1
OR
simplemachinessmfMatch1.1beta2
OR
simplemachinessmfMatch1.1beta3
OR
simplemachinessmfMatch1.1beta4
OR
simplemachinessmfMatch1.1rc1
OR
simplemachinessmfMatch1.1rc2
OR
simplemachinessmfMatch1.1rc3
OR
simplemachinessmfMatch1.1.1
OR
simplemachinessmfMatch1.1.2
OR
simplemachinessmfMatch1.1.3
OR
simplemachinessmfMatch1.1.4
OR
simplemachinessmfMatch1.1.5
OR
simplemachinessmfMatch1.1.6
OR
simplemachinessmfMatch1.1.7
OR
simplemachinessmfMatch1.1.8
OR
simplemachinessmfMatch1.1.9
OR
simplemachinessmfMatch1.1.10
OR
simplemachinessmfMatch1.1.11
Node
simplemachinessmfMatch2.0beta1
OR
simplemachinessmfMatch2.0beta2
OR
simplemachinessmfMatch2.0beta2.1
OR
simplemachinessmfMatch2.0beta3
OR
simplemachinessmfMatch2.0beta3.1
OR
simplemachinessmfMatch2.0beta4
OR
simplemachinessmfMatch2.0rc1
OR
simplemachinessmfMatch2.0rc2
OR
simplemachinessmfMatch2.0rc3
OR
simplemachinessmfMatch2.0rc4
VendorProductVersionCPE
simplemachinessmf*cpe:2.3:a:simplemachines:smf:*:*:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:*:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta4:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta4.1:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta5:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:beta6:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:rc1:*:*:*:*:*:*
simplemachinessmf1.0cpe:2.3:a:simplemachines:smf:1.0:rc2:*:*:*:*:*:*
simplemachinessmf1.0.1cpe:2.3:a:simplemachines:smf:1.0.1:*:*:*:*:*:*:*
simplemachinessmf1.0.2cpe:2.3:a:simplemachines:smf:1.0.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 571

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

73.1%

Related for CVE-2011-1131