CVE-2008-6657: CSRF
Published Apr 7, 2009
·Updated
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.
Affected Software
14 affected components
Simple Machines Simple Machines Forum=1.0.11
Simple Machines Simple Machines Forum=1.1.5
Simple Machines Simple Machines Forum=1.1.1
Simple Machines Simple Machines Forum=1.0.7
Simple Machines Simple Machines Forum=1.1.4
Simple Machines Simple Machines Forum=1.1_rc1
Simple Machines Simple Machines Forum=1.0.5
Simple Machines Simple Machines Forum=1.1.6
Simple Machines Simple Machines Forum=1.1_rc3
Simple Machines Simple Machines Forum=1.1_rc2
Simple Machines Simple Machines Forum=1.1.3
Simple Machines Simple Machines Forum=1.0.6
Simple Machines Simple Machines Forum=1.1.2
Simple Machines Simple Machines Forum=1.0.12
Event History
Apr 7, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6657?
CVE-2008-6657 has a high severity rating as it allows remote attackers to hijack admin authentication.
2
How do I fix CVE-2008-6657?
To fix CVE-2008-6657, you should upgrade your Simple Machines Forum to version 1.0.15 or 1.1.7 or later.
3
What versions are affected by CVE-2008-6657?
CVE-2008-6657 affects Simple Machines Forum versions 1.0.11 through 1.0.14 and 1.1.1 through 1.1.6.
4
Can CVE-2008-6657 be exploited without user interaction?
Yes, CVE-2008-6657 can be exploited without user interaction via crafted requests.
5
What type of vulnerability is CVE-2008-6657?
CVE-2008-6657 is a Cross-site request forgery (CSRF) vulnerability.