peter bassill · operator
$ cve CVE-2008-6659 JSON

CVE-2008-6659 EXPLOIT

5.5
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to Sources/QueryString.php and Sources/Themes.php, as demonstrated by a local .gif file in attachments/ with PHP code that was uploaded through a profile2 action to index.php.

Scoring

CVSS5.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
EPSS3.3% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-04-07
Last modified2026-06-16

Affected (1)

VendorProduct
simple machinessimple machines forum

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD