EIP-2026-112115
PRE-CVESimple Machines Forum (SMF) 1.1.8 - 'avatar' Remote PHP File Execute
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112115. PoCs published by JosS.
AI-analyzed exploit summary This exploit leverages a remote PHP file execution vulnerability in Simple Machines Forum (SMF) <= 1.1.8 by allowing an attacker to set a malicious PHP file as their avatar. When other users view the topic, the PHP file is executed, leading to information theft or other malicious actions.
Description
Simple Machines Forum (SMF) 1.1.8 - 'avatar' Remote PHP File Execute
Exploits (1)
This exploit leverages a remote PHP file execution vulnerability in Simple Machines Forum (SMF) <= 1.1.8 by allowing an attacker to set a malicious PHP file as their avatar. When other users view the topic, the PHP file is executed, leading to information theft or other malicious actions.