Simple Machines Forum 2.1

CPE Details

Simple Machines Forum 2.1
2.1
2013-10-28
13h20 +00:00
2013-10-29
13h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:simplemachines:simple_machines_forum:2.1:*:*:*:*:*:*:*

Informations

Vendor

simplemachines

Product

simple_machines_forum

Version

2.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-26982 2022-04-04 22h00 +00:00 SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose any PHP code that they wish to have executed on the server.
7.2
High
CVE-2016-5726 2017-02-09 14h00 +00:00 Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
9.8
Critical
CVE-2016-5727 2017-02-09 14h00 +00:00 LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
8.8
High
CVE-2013-4465 2013-10-25 23h00 +00:00 Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
4.6