Total vulnerabilities in the database
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "" (backslash) sequence that does not quote the "'" (single quote) character, as demonstrated via a manlabels action to index.php.
Software | From | Fixed in |
---|---|---|
simple_machines / simple_machines_forum | 1.0.11 | 1.0.11.x |
simple_machines / simple_machines_forum | 1.1.1 | 1.1.1.x |
simple_machines / simple_machines_forum | 1.0.7 | 1.0.7.x |
simple_machines / simple_machines_forum | 1.1-rc3 | 1.1-rc3.x |
simple_machines / simple_machines_forum | - | 1.1.4.x |
simple_machines / simple_machines_forum | 1.0.5 | 1.0.5.x |
simple_machines / simple_machines_forum | 1.1-rc2 | 1.1-rc2.x |
simple_machines / simple_machines_forum | 1.1.3 | 1.1.3.x |
simple_machines / simple_machines_forum | 1.0.6 | 1.0.6.x |
simple_machines / simple_machines_forum | 1.1-rc1 | 1.1-rc1.x |
simple_machines / simple_machines_forum | 1.1.2 | 1.1.2.x |
simple_machines / simple_machines_forum | 1.0.12 | 1.0.12.x |