CVE-2008-6658 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
| EPSS | 1.98% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-04-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| simple machines | simple machines forum |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Simple Machines Forum (SMF) 1.1.6 - Code Execution | 2008-11-04 |
References
→ the Explorer · watch your stack · NVD