CVE-2011-3615

Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name.  NOTE: some of these details are obtained from third party information.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
simplemachinessmf
𝑥
≤ 1.1.14
simplemachinessmf
1.0
simplemachinessmf
1.0:beta4
simplemachinessmf
1.0:beta4.1
simplemachinessmf
1.0:beta5
simplemachinessmf
1.0:beta6
simplemachinessmf
1.0:rc1
simplemachinessmf
1.0:rc2
simplemachinessmf
1.0.1
simplemachinessmf
1.0.2
simplemachinessmf
1.0.3
simplemachinessmf
1.0.4
simplemachinessmf
1.0.5
simplemachinessmf
1.0.6
simplemachinessmf
1.0.7
simplemachinessmf
1.0.8
simplemachinessmf
1.0.9
simplemachinessmf
1.0.10
simplemachinessmf
1.0.12
simplemachinessmf
1.0.13
simplemachinessmf
1.0.14
simplemachinessmf
1.0.15
simplemachinessmf
1.0.16
simplemachinessmf
1.0.17
simplemachinessmf
1.0.18
simplemachinessmf
1.0.19
simplemachinessmf
1.0.20
simplemachinessmf
1.0.21
simplemachinessmf
1.1
simplemachinessmf
1.1:beta1
simplemachinessmf
1.1:beta2
simplemachinessmf
1.1:beta3
simplemachinessmf
1.1:beta4
simplemachinessmf
1.1:rc1
simplemachinessmf
1.1:rc2
simplemachinessmf
1.1:rc3
simplemachinessmf
1.1.1
simplemachinessmf
1.1.2
simplemachinessmf
1.1.3
simplemachinessmf
1.1.4
simplemachinessmf
1.1.5
simplemachinessmf
1.1.6
simplemachinessmf
1.1.7
simplemachinessmf
1.1.8
simplemachinessmf
1.1.9
simplemachinessmf
1.1.10
simplemachinessmf
1.1.11
simplemachinessmf
1.1.12
simplemachinessmf
1.1.13
simplemachinessmf
2.0
simplemachinessmf
2.0:beta1
simplemachinessmf
2.0:beta2
simplemachinessmf
2.0:beta2.1
simplemachinessmf
2.0:beta3
simplemachinessmf
2.0:beta3.1
simplemachinessmf
2.0:beta4
simplemachinessmf
2.0:rc1
simplemachinessmf
2.0:rc1.2
simplemachinessmf
2.0:rc2
simplemachinessmf
2.0:rc3
simplemachinessmf
2.0:rc4
simplemachinessmf
2.0:rc5
𝑥
= Vulnerable software versions