MEDIUM
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header
Published Apr 29, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.18%
Description
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
Affected products
No data.
OR
- ≤ 1.1.9
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.0.10
- 1.0.12
- 1.0.13
- 1.0.14
- 1.0.15
- 1.0.16
- 1.0.17
- 1.0.18
- 1.0.19
- 1.0.20
- 1.0.21
- 1.0.22
- 1.0.23
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.10
- 1.1.11
- 1.1.12
- 1.1.13
- 1.1.14
- 1.1.15
- 1.1.16
- 1.1.17
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://download.simplemachines.org/index.php?thanks%3Bfilename=smf_2-0-6_changelog.txt x_refsource_CONFIRM
- http://seclists.org/fulldisclosure/2013/Dec/83 mailing-listx_refsource_FULLDISC
- http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software/ x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2013/12/30/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2013/12/30/3 mailing-listx_refsource_MLIST
| Link | Providers | Tags |
|---|---|---|
| http://download.simplemachines.org/index.php?thanks%3Bfilename=smf_2-0-6_changelog.txt | x_refsource_CONFIRM | |
| http://seclists.org/fulldisclosure/2013/Dec/83 | mailing-listx_refsource_FULLDISC | |
| http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software/ | x_refsource_MISC | |
| http://www.openwall.com/lists/oss-security/2013/12/30/1 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2013/12/30/3 | mailing-listx_refsource_MLIST |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 29, 2014
Updated Aug 6, 2024
Reserved Dec 29, 2013
Link CVE-2013-7234
CISA Vulnrichment
Updated n/a