peter bassill · operator
$ cve CVE-2008-6658 JSON

CVE-2008-6658 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS1.98% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-04-07
Last modified2026-06-16

Affected (1)

VendorProduct
simple machinessimple machines forum

Public exploits

SourceTitleDate
exploit-dbSimple Machines Forum (SMF) 1.1.6 - Code Execution2008-11-04

References

→ the Explorer  ·  watch your stack  ·  NVD