High severity8.8NVD Advisory· Published Feb 9, 2017· Updated May 13, 2026
CVE-2016-5727
CVE-2016-5727
Description
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
Affected products
1- cpe:2.3:a:simplemachines:simple_machines_forum:2.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.openwall.com/lists/oss-security/2016/06/10/7nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2016/06/18/1nvdMailing ListPatchThird Party Advisory
- github.com/SimpleMachines/SMF2.1/commit/19e560b9f3e8fc6d7d9d60c1ff617b5ed5c08008nvdIssue TrackingPatchThird Party Advisory
- github.com/SimpleMachines/SMF2.1/issues/3522nvdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.