Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Simple Machines Forum Password Reset Security Bypass Vulnerability

Simple Machines Forum is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-reset feature.

An attacker can exploit this issue to gain administrative access to the application, which may allow the attacker to compromise the application; other attacks are also possible.

Versions up to and including Simple Machines Forum 1.1.7 are vulnerable.

UPDATE (February 6, 2009): The vendor indicates that this issue was resolved in Simple Machines Forum 1.0.14 and 1.1.6.







 

Privacy Statement
Copyright 2008, SecurityFocus