Required CVE Record Information
Description
The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situations where a temporary table has not been created, which might allow remote attackers to obtain sensitive information via a search.
References 4 Total
- openwall.com: [oss-security] 20110222 CVE request: simple machines forum before 1.1.13 mailing-list
- http://www.simplemachines.org/community/index.php?topic=421547.0
- openwall.com: [oss-security] 20110302 Re: CVE request: simple machines forum before 1.1.13 mailing-list
- http://custom.simplemachines.org/mods/downloads/smf_patch_2.0-RC4_security.zip
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- openwall.com: [oss-security] 20110222 CVE request: simple machines forum before 1.1.13 mailing-listx_transferred
- http://www.simplemachines.org/community/index.php?topic=421547.0 x_transferred
- openwall.com: [oss-security] 20110302 Re: CVE request: simple machines forum before 1.1.13 mailing-listx_transferred
- http://custom.simplemachines.org/mods/downloads/smf_patch_2.0-RC4_security.zip x_transferred