Simple Machines Forum 2.1

CPE Details

Simple Machines Forum 2.1
2.1
2013-10-28
13h20 +00:00
2013-10-29
13h39 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:simplemachines:simple_machines_forum:2.1:*:*:*:*:*:*:*

Informations

Vendor

simplemachines

Product

simple_machines_forum

Version

2.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-26982 2022-04-04 22h00 +00:00 SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose any PHP code that they wish to have executed on the server.
7.2
Haute
CVE-2016-5726 2017-02-09 14h00 +00:00 Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
9.8
Critique
CVE-2016-5727 2017-02-09 14h00 +00:00 LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
8.8
Haute
CVE-2013-4465 2013-10-25 23h00 +00:00 Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
4.6