vendor:
SMF
by:
Xianur0
8.8
CVSS
HIGH
Multiple Vulnerabilities
N/A
CWE
Product Name: SMF
Affected Version From: 1.1.7 and below
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2009
SMF Destroyer 0.1 By Xianur0 [Priv8]
SMF Destroyer 0.1 is a perl script which can be used to exploit multiple vulnerabilities in Simple Machines Forum (SMF). It can be used to crack links password recovery, find temporary files executed by mods, DB function flood by error log, file path disclosure, list installed mods (useful to find mods vulnerable), etc.
Mitigation:
Upgrade to the latest version of SMF