CVE-2008-6544
Simple Machines Forum 1.1.4 - Remote Code Execution via settings[default_theme_dir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6544. PoCs published by Sibertrwolf.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Simple Machines Forum 1.1.4. It allows an attacker to include arbitrary remote files containing malicious PHP code by manipulating the `settings[default_theme_dir]` or `settings[theme_dir]` parameters.
Description
Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter to Sources/Themes.php. NOTE: CVE and multiple third parties dispute this issue because the files contain a protection mechanism against direct request
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Simple Machines Forum 1.1.4. It allows an attacker to include arbitrary remote files containing malicious PHP code by manipulating the `settings[default_theme_dir]` or `settings[theme_dir]` parameters.