CVE-2008-3072

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
08/07/2008
Last modified:
09/04/2025

Description

Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simple_machines:simple_machines_forum:*:*:*:*:*:*:*:* 1.0.12 (including)
cpe:2.3:a:simple_machines:simple_machines_forum:*:*:*:*:*:*:*:* 1.1.4 (including)