CVE-2013-4465: Medium severity SimpleMachines Simple Machines Forum vulnerability
Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4465?
CVE-2013-4465 is categorized as a medium to high severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary code.
How do I fix CVE-2013-4465?
To fix CVE-2013-4465, upgrade to Simple Machines Forum versions 2.0.6 or 2.1 and ensure that the file upload functionality is properly secured.
Who is affected by CVE-2013-4465?
CVE-2013-4465 affects users of Simple Machines Forum versions prior to 2.0.6 and all versions of 1.x.
What type of vulnerability is CVE-2013-4465?
CVE-2013-4465 is an unrestricted file upload vulnerability which can be exploited to upload malicious files.
Can I exploit CVE-2013-4465 without authentication?
No, exploiting CVE-2013-4465 requires authentication as it targets remote authenticated users.