CVE-2007-5646

Simple Machines Forum - SQL Injection

Title source: rule

Description

SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michael Brooks · perlwebappsphp
https://www.exploit-db.com/exploits/4547

Scores

EPSS 0.0168
EPSS Percentile 82.2%

Details

CWE
CWE-89
Status published
Products (2)
simple_machines/simple_machines_forum 1.0.11
simple_machines/simple_machines_forum 1.1.3
Published Oct 23, 2007
Tracked Since Feb 18, 2026