CVE-2008-6658

Simple Machines Forum - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/6993

Scores

EPSS 0.0258
EPSS Percentile 85.6%

Details

CWE
CWE-22
Status published
Products (14)
simple_machines/simple_machines_forum 1.0.5
simple_machines/simple_machines_forum 1.0.6
simple_machines/simple_machines_forum 1.0.7
simple_machines/simple_machines_forum 1.0.11
simple_machines/simple_machines_forum 1.0.12
simple_machines/simple_machines_forum 1.1.1
simple_machines/simple_machines_forum 1.1.2
simple_machines/simple_machines_forum 1.1.3
simple_machines/simple_machines_forum 1.1.4
simple_machines/simple_machines_forum 1.1.5
... and 4 more
Published Apr 07, 2009
Tracked Since Feb 18, 2026