Vulnerability Description
NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simple Machines | Simple Machines Forum | <= 1.1_rc1 |
References
- http://archives.neohapsis.com/archives/bugtraq/2005-12/0090.html
- http://www.securityfocus.com/archive/1/419068/100/0/threaded
- http://www.securityfocus.com/archive/1/419105/100/0/threaded
- http://www.securityfocus.com/archive/1/419250/100/0/threaded
- http://www.securityfocus.com/archive/1/419535/100/0/threaded
- http://www.securityfocus.com/bid/15791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23546
- http://archives.neohapsis.com/archives/bugtraq/2005-12/0090.html
- http://www.securityfocus.com/archive/1/419068/100/0/threaded
- http://www.securityfocus.com/archive/1/419105/100/0/threaded
- http://www.securityfocus.com/archive/1/419250/100/0/threaded
- http://www.securityfocus.com/archive/1/419535/100/0/threaded
- http://www.securityfocus.com/bid/15791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23546
FAQ
What is CVE-2005-4159?
CVE-2005-4159 is a vulnerability with a CVSS score of 7.5 (HIGH). NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute ...
How severe is CVE-2005-4159?
CVE-2005-4159 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4159?
Check the references section above for vendor advisories and patch information. Affected products include: Simple Machines Simple Machines Forum.