CVE-2007-3942 describes a disputed directory traversal vulnerability in Simple Machines Forum (SMF) version 1.1.3. It was initially reported to allow remote attackers to include local files through unspecified vectors related to the 'sourcedir' parameter or 'actionArray' hash. The vulnerability has a CVSS score of 5.8 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and potentially leading to partial confidentiality and integrity impacts. Despite its initial reporting, both the CVE and multiple third parties dispute its validity due to the parameters being defined before use, and there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.3CPE matchmatch criteria | cpe:2.3:a:simple_machines:simple_machines_forum:1.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.