CVE-2008-6971

Simplemachines Smf - Credentials Management

Title source: rule

Description

The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Raz0r · phpwebappsphp
https://www.exploit-db.com/exploits/6392

Scores

EPSS 0.0571
EPSS Percentile 90.5%

Details

CWE
CWE-255
Status published
Products (7)
simplemachines/smf 1.0.12
simplemachines/smf 1.0.13
simplemachines/smf 1.1.4
simplemachines/smf 1.1.5
simplemachines/smf 2.0 rc1.2
simplemachines/smf 2.0-beta2
simplemachines/smf 2.0-beta3
Published Aug 13, 2009
Tracked Since Feb 18, 2026