SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose any PHP code that they wish to have executed on the server.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSimplemachines Simple Machines Forum
APPSimplemachines≤ 2.1.1
Powiązane podatności
SMF: obejście kontroli dostępu w wyszukiwaniu prywatnych wiadomości
PHP Object Injection w Simple Machines Forum 2.1 — zdalne wykonanie kodu
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On ...
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in instal...
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=e...