CVE-2007-5646
Simple Machines Forum - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Michael Brooks · perlwebappsphp
https://www.exploit-db.com/exploits/4547
References (8)
Scores
EPSS
0.0168
EPSS Percentile
82.2%
Details
CWE
CWE-89
Status
published
Products (2)
simple_machines/simple_machines_forum
1.0.11
simple_machines/simple_machines_forum
1.1.3
Published
Oct 23, 2007
Tracked Since
Feb 18, 2026