Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37xx-h4m8-x8wx

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

EPSS

Процентиль: 69%
0.0059
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

EPSS

Процентиль: 69%
0.0059
Низкий