CVE-2006-7013: High severity Simple Machines Simple Machines Forum vulnerability
DISPUTED QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7013?
CVE-2006-7013 is considered a medium severity vulnerability due to its potential for IP address spoofing.
How do I fix CVE-2006-7013?
To fix CVE-2006-7013, upgrade Simple Machines Forum to version 1.0.8 or later, or 1.1.x or later.
Who is affected by CVE-2006-7013?
CVE-2006-7013 affects all versions of Simple Machines Forum up to and including 1.0.7 and 1.1rc2.
What kind of attack is possible with CVE-2006-7013?
CVE-2006-7013 allows remote attackers to spoof IP addresses and bypass banning mechanisms.
Is CVE-2006-7013 still a concern for current versions?
CVE-2006-7013 is not a concern for current versions as subsequent releases have patched the vulnerability.