LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/06/10/7 | Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/06/18/1 | Mailing List Patch Third Party Advisory |
https://github.com/SimpleMachines/SMF2.1/commit/19e560b9f3e8fc6d7d9d60c1ff617b5ed5c08008#diff-513c4f9c501cbefcc14420c01848f23c | Issue Tracking Patch Third Party Advisory |
https://github.com/SimpleMachines/SMF2.1/issues/3522 | Issue Tracking Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-02-09T15:00:00
Updated: 2017-02-09T13:57:01
Reserved: 2016-06-18T00:00:00
Link: CVE-2016-5727
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-02-09T15:59:01.160
Modified: 2017-02-23T18:25:11.980
Link: CVE-2016-5727
JSON object: View
Redhat Information
No data.
CWE