CVE-2008-0284

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simple_machines:simple_machines_smf:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:41

Type Values Removed Values Added
References () http://securityreason.com/securityalert/3540 - () http://securityreason.com/securityalert/3540 -
References () http://www.securityfocus.com/archive/1/486074/100/0/threaded - () http://www.securityfocus.com/archive/1/486074/100/0/threaded -
References () http://www.securityfocus.com/bid/27218 - () http://www.securityfocus.com/bid/27218 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39585 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/39585 -

Information

Published : 2008-01-15 21:00

Updated : 2024-11-21 00:41


NVD link : CVE-2008-0284

Mitre link : CVE-2008-0284

CVE.ORG link : CVE-2008-0284


JSON object : View

Products Affected

simple_machines

  • simple_machines_smf
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')