peter bassill · operator
$ cve CVE-2005-4891 JSON

CVE-2005-4891 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 1.7% (pctl 77)

Patch early

A public exploit exists.

Description

Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.74% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2020-01-15
Last modified2026-06-16

Affected (1)

VendorProduct
simplemachinessimple machine forum

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD