CVE-2008-6658

Simple Machines Forum 1.0-1.0.14 and 1.1-1.1.6 - Authenticated Path Traversal via Package Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6658. PoCs published by Charles Fol.

AI-analyzed exploit summary This exploit leverages a combination of vulnerabilities in SMF 1.1.6, including CSRF and improper file handling, to achieve remote code execution by tricking an admin into installing a malicious package via an image tag in a forum post.

Description

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/6993

This exploit leverages a combination of vulnerabilities in SMF 1.1.6, including CSRF and improper file handling, to achieve remote code execution by tricking an admin into installing a malicious package via an image tag in a forum post.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Simple Machines Forum (SMF) 1.1.6
Auth required
Prerequisites: Valid user credentials · Admin interaction to view the post
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50070
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6993

Scores

EPSS 0.0198
EPSS Percentile 78.0%

Details

CWE
CWE-22
Status published
Products (14)
simple_machines/simple_machines_forum 1.0.5
simple_machines/simple_machines_forum 1.0.6
simple_machines/simple_machines_forum 1.0.7
simple_machines/simple_machines_forum 1.0.11
simple_machines/simple_machines_forum 1.0.12
simple_machines/simple_machines_forum 1.1.1
simple_machines/simple_machines_forum 1.1.2
simple_machines/simple_machines_forum 1.1.3
simple_machines/simple_machines_forum 1.1.4
simple_machines/simple_machines_forum 1.1.5
... and 4 more
Published Apr 07, 2009
Tracked Since Feb 18, 2026