CVE-2010-2099: High severity e107 e107 vulnerability
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2099?
CVE-2010-2099 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2010-2099?
To fix CVE-2010-2099, upgrade to e107 version 0.7.21 or later which includes the necessary patches.
What are the affected versions related to CVE-2010-2099?
CVE-2010-2099 affects e107 versions 0.7.20 and earlier, as well as various earlier beta versions.
Can CVE-2010-2099 be exploited easily?
Yes, CVE-2010-2099 can be exploited easily by remote attackers to execute arbitrary PHP code.
What is the impact of CVE-2010-2099?
The impact of CVE-2010-2099 can result in full control over the affected server, leading to data theft or corruption.