Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSimplemachines Simple Machines Forum
APPSimplemachines2.0.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEPath Traversal
CWE
Powiązane podatności
CVE-2018-10305CRITICAL9.8PL ✓ten sam produkt
SMF: obejście kontroli dostępu w wyszukiwaniu prywatnych wiadomości
CVE-2016-5726CRITICAL9.8PL ✓ten sam produkt
PHP Object Injection w Simple Machines Forum 2.1 — zdalne wykonanie kodu
CVE-2022-26982HIGH7.2ten sam produkt
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by ...
CVE-2009-5068HIGH7.2ten sam produkt
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On ...
CVE-2013-7468HIGH8.1ten sam produkt
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=e...