CVE-2013-7236
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0059 (0.6%)
Percentil: 69.1%
EPSS: 2026-05-06
Afecta
simplemachines:simple_machines_forumDescripción técnica
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
Publicada: 29/4/2014, 14:38:47
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://seclists.org/fulldisclosure/2013/Dec/83
- http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software/
- http://www.openwall.com/lists/oss-security/2013/12/30/1
- http://www.openwall.com/lists/oss-security/2013/12/30/3
- http://seclists.org/fulldisclosure/2013/Dec/83
- http://www.jakoblell.com/blog/2013/12/13/multiple-vulnerabilities-in-smf-forum-software/
- http://www.openwall.com/lists/oss-security/2013/12/30/1
- http://www.openwall.com/lists/oss-security/2013/12/30/3