Vulnerability Description
Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read arbitrary local files, lock topics, and possibly have other security impacts. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Simple Machines Forum.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simple Machines | Simple Machines Forum | <= 1.0.7 |
References
- http://retrogod.altervista.org/smf_11rc2_local_incl.html
- http://retrogod.altervista.org/smf_11rc2_lock.html
- http://securityreason.com/securityalert/1475
- http://www.securityfocus.com/archive/1/444053/100/100/threaded
- http://www.simplemachines.org/community/index.php?topic=107112.0
- http://www.simplemachines.org/community/index.php?topic=107135.0
- http://retrogod.altervista.org/smf_11rc2_local_incl.html
- http://retrogod.altervista.org/smf_11rc2_lock.html
- http://securityreason.com/securityalert/1475
- http://www.securityfocus.com/archive/1/444053/100/100/threaded
- http://www.simplemachines.org/community/index.php?topic=107112.0
- http://www.simplemachines.org/community/index.php?topic=107135.0
FAQ
What is CVE-2006-4467?
CVE-2006-4467 is a vulnerability with a CVSS score of 7.5 (HIGH). Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric param...
How severe is CVE-2006-4467?
CVE-2006-4467 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4467?
Check the references section above for vendor advisories and patch information. Affected products include: Simple Machines Simple Machines Forum.