- Description
- Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors.
- Source
- cve@mitre.org
- NVD status
- Deferred
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- nvd@nist.gov
- CWE-189
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:simple_machines:simple_machines_forum:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1E2DE6F-5256-404C-88A0-9EB9A1B7586C",
"versionEndIncluding": "1.0.12"
},
{
"criteria": "cpe:2.3:a:simple_machines:simple_machines_forum:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EFF60548-26B3-4213-BC8A-D8CD0D4B76C7",
"versionEndIncluding": "1.1.4"
}
],
"operator": "OR"
}
]
}
]