CVE-2009-5068
HIGHSimple Machines Forum <= 2.0.3 - Unauthenticated Arbitrary File Read via settings.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-5068.
AI-analyzed exploit summary The document describes multiple vulnerabilities in Simple Machines Forum, including RCE, XSS, CSRF, information disclosure, and DoS. It provides example URIs and payloads for exploitation but lacks functional exploit code.
Description
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.
Exploits (1)
The document describes multiple vulnerabilities in Simple Machines Forum, including RCE, XSS, CSRF, information disclosure, and DoS. It provides example URIs and payloads for exploitation but lacks functional exploit code.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H