4
CVSSv2

CVE-2008-6658

Published: 07/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 prior to 1.0.15 and 1.1 prior to 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

simple machines simple machines forum 1.1_rc1

simple machines simple machines forum 1.1_rc2

simple machines simple machines forum 1.0.5

simple machines simple machines forum 1.0.12

simple machines simple machines forum 1.1.3

simple machines simple machines forum 1.1.4

simple machines simple machines forum 1.1.5

simple machines simple machines forum 1.0.6

simple machines simple machines forum 1.0.7

simple machines simple machines forum 1.1.6

simple machines simple machines forum 1.1.1

simple machines simple machines forum 1.0.11

simple machines simple machines forum 1.1_rc3

simple machines simple machines forum 1.1.2

Exploits

<?php # # Simple Machines Forum (SMF) 116 Remote Code Execution Exploit # Credits: Charles FOL <charlesfol[at]hotmailfr> # URL: realolympe-networkcom/ # # Note: other versions are maybe vulnerable, not tested # # SMF suffers from multiples vulnerabilities # Combining some of them, we can obtain a remote code execution on t ...