Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value, related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:10

Updated: 2022-10-03T16:15:10

Reserved: 2022-10-03T00:00:00


Link: CVE-2011-1130

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2011-06-21T02:52:42.420

Modified: 2012-12-20T05:00:00.000


Link: CVE-2011-1130

JSON object: View

cve-icon Redhat Information

No data.

CWE