CVE-2013-7466

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
07/03/2019
Last modified:
12/03/2019

Description

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simplemachines:simple_machines_forum:2.0.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools