CVE-2011-3615: SQL Injection
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3615?
CVE-2011-3615 is considered critical due to its multiple SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2011-3615?
To fix CVE-2011-3615, upgrade Simple Machines Forum to versions 1.1.15 or 2.0.1 or later, which contain patches for these vulnerabilities.
Which versions of Simple Machines Forum are affected by CVE-2011-3615?
CVE-2011-3615 affects Simple Machines Forum versions before 1.1.15 and 2.x before 2.0.1.
What types of attacks can exploit CVE-2011-3615?
CVE-2011-3615 can be exploited by SQL injection attacks that manipulate HTML entities or display names.
Are there any workarounds for CVE-2011-3615?
There are no specific workarounds for CVE-2011-3615; updating to a secure version is the recommended mitigation.