CVE-2011-1130: Input Validation
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value, related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1130?
CVE-2011-1130 has a high severity level due to its potential for SQL injection and remote attack risks.
How do I fix CVE-2011-1130?
To fix CVE-2011-1130, upgrade to Simple Machines Forum versions 1.1.13 or 2.0 RC5 or later.
What types of attacks are possible due to CVE-2011-1130?
CVE-2011-1130 can allow attackers to conduct SQL injection attacks, obtain sensitive information, or cause denial of service.
Which versions of Simple Machines Forum are affected by CVE-2011-1130?
CVE-2011-1130 affects Simple Machines Forum versions prior to 1.1.13 and 2.x before 2.0 RC5.
Is CVE-2011-1130 easy to exploit?
Yes, CVE-2011-1130 can be exploited easily by attackers who provide crafted values to the start parameter.