ZeroHour

CVE-2016-5726

CVSS 3.0
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.

Vendors
simplemachines
Products
simple machines forum
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.