Skip to main content
Medium August 23, 2011

Anti-CSRF Filter Bypass SMF 2.0 / 1.1.14

The [img] BBCode tag anti-CSRF filter can be bypassed due to incorrect parsing of the 'action' variable, because of this it is possible to execute CSRF successfully.

CVSS Score

4.3 / 10.0

Severity

Medium

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Advisory

SoftwareSimple Machines Forum (SMF)
VersionsSMF 1.1.14 - 2.0
ImpactCross-Site Request Forgery via BBCode image tag
Websec AdvisoryWS11-15

Description

When a user posts a URL inside an [img] BBCode tag and the URL contains an action= parameter, SMF's anti-CSRF filter rewrites action=something to action-something to block the request.

Appending a null byte (%00) to the end of the variable name bypasses the substitution, and the request executes as-is. The resulting image tag triggers a CSRF against any viewer of the post.

Remediation

Upgrade SMF to a release where the [img] BBCode filter handles null bytes correctly.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory
High December 19, 2013

Arbitrary Command Execution in Alcatel-Lucent I-240W-Q

The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.

Severity:
CVSS: 8.0
View advisory