CVE-2016-5726
—CVSS 3.0
9.8 critical
EPSS
2%p74
Published
()
Modified
Description
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
- Vendors
- simplemachines
- Products
- simple machines forum
- Weakness
- CWE-94
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.