CVE-2013-7466: Path Traversal
Published Mar 7, 2019
·Updated
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the dbtype parameter if install.php remains present after installation.
Affected Software
1 affected component
SimpleMachines Simple Machines Forum=2.0.4
Event History
Mar 7, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2013-7466.
2
What is the severity of CVE-2013-7466?
The severity of CVE-2013-7466 is high.
3
How does CVE-2013-7466 affect Simple Machines Forum (SMF)?
CVE-2013-7466 affects Simple Machines Forum (SMF) version 2.0.4.
4
How can the local file inclusion vulnerability in Simple Machines Forum (SMF) version 2.0.4 be exploited?
The local file inclusion vulnerability in Simple Machines Forum (SMF) version 2.0.4 can be exploited through the install.php script using directory traversal.
5
Is there a fix available for CVE-2013-7466?
Yes, the fix for CVE-2013-7466 is to remove or secure the install.php script after installation.