First published: Sun Dec 11 2005(Updated: )
** DISPUTED ** NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Machines Forum | <=1.1_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-4159 is disputed, but it is categorized as an SQL injection vulnerability that could lead to remote code execution.
To fix CVE-2005-4159, upgrade your Simple Machines Forum to a version later than 1.1 rc1.
CVE-2005-4159 affects Simple Machines Forum version 1.1 rc1 and earlier.
Yes, CVE-2005-4159 can be exploited remotely by attackers to execute arbitrary SQL commands.
While the vulnerability is from 2005, it is still a concern for users who have not updated to a secure version.