Simple Machines Forum < 1.1.7 Incomplete BBcode Block Security Bypass
medium Nessus Network Monitor Plugin ID 4703
Synopsis
The remote host is vulnerable to a security bypass flaw.
Description
The remote host is running Simple Machines Forum (SMF), a web forum. This version of SMF is vulnerable to a flaw where attackers can bypass security filtering by surrounding the content with an incomplete BBcode block. Successful exploitation would result in the attacker posting banned content within the web content.