Unrated severityNVD Advisory· Published Aug 13, 2009· Updated Apr 23, 2026
CVE-2008-6971
CVE-2008-6971
Description
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.
Affected products
7cpe:2.3:a:simplemachines:smf:1.0.12:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:simplemachines:smf:1.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:1.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0-beta2:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0-beta3:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc1.2:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.simplemachines.org/community/index.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/31053nvdExploit
- secunia.com/advisories/31750nvdVendor Advisory
- osvdb.org/47945nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44931nvd
- www.exploit-db.com/exploits/6392nvd
News mentions
0No linked articles in our index yet.