ZeroHour

CVE-2016-5727

CVSS 3.0
8.8 high
EPSS
2%p73
Published
()
Modified
Description

LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.

Vendors
simplemachines
Products
simple machines forum
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.