CVE-2007-0399
Simple Machines Forum 1.1 RC3 - Authenticated Cross-Site Scripting via PM Recipient or BCC Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0399. PoCs published by Aria-Security Team.
AI-analyzed exploit summary The provided text describes an HTML-injection vulnerability in SMF (Simple Machines Forum) due to insufficient input sanitization. It allows attacker-supplied HTML/script code execution in the context of the affected site, requiring valid account credentials to exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.
Exploits (1)
The provided text describes an HTML-injection vulnerability in SMF (Simple Machines Forum) due to insufficient input sanitization. It allows attacker-supplied HTML/script code execution in the context of the affected site, requiring valid account credentials to exploit.