Vulnerabilities > CVE-2005-2817 - Information Disclosure vulnerability in Simple Machines Simple Machines Forum 1.0.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | SMF_AVATAR_CODE_INJECTION.NASL |
description | The remote host is running Simple Machines Forum (SMF), an open source web forum application written in PHP. The installed version of SMF on the remote host does not properly sanitize the URI supplied for the user avatar. An attacker who is registered in the affected application can exploit this flaw to run scripts each time a forum user accesses the malicious avatar, eg collecting forum usage information, launching attacks against users |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19550 |
published | 2005-08-31 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19550 |
title | Simple Machines Forum Avatar Information Disclosure Vulnerability |
code |
|