CVE Vulnerabilities

CVE-2010-2099

Published: May 27, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.

Affected Software

NameVendorStart VersionEnd Version
E107E107*0.7.20 (including)
E107E1070.6_10 (including)0.6_10 (including)
E107E1070.6_11 (including)0.6_11 (including)
E107E1070.6_12 (including)0.6_12 (including)
E107E1070.6_13 (including)0.6_13 (including)
E107E1070.6_14 (including)0.6_14 (including)
E107E1070.6_15 (including)0.6_15 (including)
E107E1070.6_15a (including)0.6_15a (including)
E107E1070.7 (including)0.7 (including)
E107E1070.7.0 (including)0.7.0 (including)
E107E1070.7.1 (including)0.7.1 (including)
E107E1070.7.2 (including)0.7.2 (including)
E107E1070.7.3 (including)0.7.3 (including)
E107E1070.7.4 (including)0.7.4 (including)
E107E1070.7.5 (including)0.7.5 (including)
E107E1070.7.6 (including)0.7.6 (including)
E107E1070.7.7 (including)0.7.7 (including)
E107E1070.7.8 (including)0.7.8 (including)
E107E1070.7.9 (including)0.7.9 (including)
E107E1070.7.10 (including)0.7.10 (including)
E107E1070.7.11 (including)0.7.11 (including)
E107E1070.7.12 (including)0.7.12 (including)
E107E1070.7.13 (including)0.7.13 (including)
E107E1070.7.14 (including)0.7.14 (including)
E107E1070.7.15 (including)0.7.15 (including)
E107E1070.7.16 (including)0.7.16 (including)
E107E1070.7.17 (including)0.7.17 (including)
E107E1070.7.18 (including)0.7.18 (including)
E107E1070.7.19 (including)0.7.19 (including)
E107E1070.545 (including)0.545 (including)
E107E1070.547-beta (including)0.547-beta (including)
E107E1070.548-beta (including)0.548-beta (including)
E107E1070.549-beta (including)0.549-beta (including)
E107E1070.551-beta (including)0.551-beta (including)
E107E1070.552-beta (including)0.552-beta (including)
E107E1070.553-beta (including)0.553-beta (including)
E107E1070.554 (including)0.554 (including)
E107E1070.554-beta (including)0.554-beta (including)
E107E1070.555-beta (including)0.555-beta (including)
E107E1070.600 (including)0.600 (including)
E107E1070.601 (including)0.601 (including)
E107E1070.602 (including)0.602 (including)
E107E1070.603 (including)0.603 (including)
E107E1070.604 (including)0.604 (including)
E107E1070.605 (including)0.605 (including)
E107E1070.606 (including)0.606 (including)
E107E1070.607 (including)0.607 (including)
E107E1070.608 (including)0.608 (including)
E107E1070.609 (including)0.609 (including)
E107E1070.610 (including)0.610 (including)
E107E1070.611 (including)0.611 (including)
E107E1070.612 (including)0.612 (including)
E107E1070.613 (including)0.613 (including)
E107E1070.614 (including)0.614 (including)
E107E1070.615 (including)0.615 (including)
E107E1070.615a (including)0.615a (including)
E107E1070.616 (including)0.616 (including)
E107E1070.617 (including)0.617 (including)
E107E1070.6171 (including)0.6171 (including)
E107E1070.6172 (including)0.6172 (including)
E107E1070.6173 (including)0.6173 (including)
E107E1070.6174 (including)0.6174 (including)
E107E1070.6175 (including)0.6175 (including)

References