CVE-2008-6658
Simple Machines Forum - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/6993
Scores
EPSS
0.0258
EPSS Percentile
85.6%
Details
CWE
CWE-22
Status
published
Products (14)
simple_machines/simple_machines_forum
1.0.5
simple_machines/simple_machines_forum
1.0.6
simple_machines/simple_machines_forum
1.0.7
simple_machines/simple_machines_forum
1.0.11
simple_machines/simple_machines_forum
1.0.12
simple_machines/simple_machines_forum
1.1.1
simple_machines/simple_machines_forum
1.1.2
simple_machines/simple_machines_forum
1.1.3
simple_machines/simple_machines_forum
1.1.4
simple_machines/simple_machines_forum
1.1.5
... and 4 more
Published
Apr 07, 2009
Tracked Since
Feb 18, 2026