Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-3615

EPSS 0.46% · P64
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-3615

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name. NOTE: some of these details are obtained from third party information.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Simple Machines Forum 跨站脚本攻击漏洞和帮助钓鱼攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Simple Machines Forum(SMF)是美国SMF团队开发的一套开源、专业级的论坛软件包,它包含一个能够完全掌控论坛界面和布局的可定制模板引擎,并提供一种可实现论坛与网站相互给合的SSI(Server Side Includes)技术。 Simple Machines Forum 1.1.15之前的1.x版本和2.0.1之前的2.x 版本中存在跨站脚本攻击漏洞和帮助钓鱼攻击漏洞。攻击者可利用这些漏洞误导用户相信他们查看的合法站点,窃取基于cookie的认证证书,并在受影响站点上下文受信任用户
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-3615

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-3615

Please Login to view more intelligence information

Same Patch Batch · n/a · 2011-10-24 · 9 CVEs total

CVE-2011-4171IBM WebSphere ILOG Rule Team Server ‘content/error.jsp’ 跨站脚本攻击漏洞
CVE-2011-4172KENT-WEB WEB FORUM 多个跨站脚本攻击漏洞
CVE-2011-4173Simple Machines Forum 跨站请求伪造漏洞
CVE-2011-2655Novell ZENworks Handheld Management 多个远程代码执行漏洞
CVE-2011-2656Novell ZENworks Handheld Management 多个远程代码执行漏洞
CVE-2011-3383Kent Web Forum 跨站脚本攻击漏洞
CVE-2011-3983KENT-WEB WEB FORUM ‘cookies’ 跨站脚本攻击漏洞
CVE-2011-3984KENT-WEB WEB FORUM ‘web form entries’ 跨站脚本攻击漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-3615

No comments yet


Leave a comment