oss-sec mailing list archives

CVE request: Simple Machines Forum (SMF) <= 2.0.5 - multiple vulnerabilities


From: Henri Salo <henri () nerv fi>
Date: Sun, 15 Sep 2013 21:27:56 +0300

Please assign 2013 CVE for SMF vulnerabilities, thanks. Fixes at least XSS
issues. No reply from vendor when I asked if there is CVE(s) assigned already.

Advisory: http://www.simplemachines.org/community/index.php?topic=509417
Diff: http://custom.simplemachines.org/upgrades/index.php?action=upgrade;file=smf_patch_2.0.5.tar.gz;smf_version=2.0.4

Other references:
http://osvdb.org/96323
http://secunia.com/advisories/54384/

---
Henri Salo

Attachment: signature.asc
Description: Digital signature


Current thread: