CVE Database
/

CVE-2009-5068

Back to search

CVE-2009-5068

Published: Jan 15, 2020

Modified: Aug 7, 2024

PUBLISHED

Description

There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.

VendorProductVersions

SMF

SMF

affected
through 2.0.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now