oss-sec mailing list archives

CVE-request: SMF index.php msg parameter SQL-injection (2005)


From: Henri Salo <henri () nerv fi>
Date: Fri, 14 Sep 2012 15:40:32 +0300

Hello list,

Old SQL-injection security issue in SMF does not have CVE-identifier. Could you please assign one from year 2005, 
thanks.

Affected versions: <= 1.0.4
Fixed in 1.0.5

References:
http://osvdb.org/17458
http://secunia.com/advisories/15784/

- Henri Salo
ps. never too late


Current thread: