Arbitrary PHP Code Execution Vulnerability in Simple Machines Forum (SMF) 2.1

Arbitrary PHP Code Execution Vulnerability in Simple Machines Forum (SMF) 2.1

CVE-2016-5727 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.

Learn more about our User Device Pen Test.