LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/06/10/7 | Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/06/18/1 | Mailing List Patch Third Party Advisory |
https://github.com/SimpleMachines/SMF2.1/commit/19e560b9f3e8fc6d7d9d60c1ff617b5ed5c08008#diff-513c4f9c501cbefcc14420c01848f23c | Issue Tracking Patch Third Party Advisory |
https://github.com/SimpleMachines/SMF2.1/issues/3522 | Issue Tracking Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2017-02-09 15:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-5727
Mitre link : CVE-2016-5727
CVE.ORG link : CVE-2016-5727
JSON object : View
Products Affected
simplemachines
- simple_machines_forum
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')