CVE Vulnerabilities

CVE-2010-2099

Published: May 27, 2010 | Modified: May 28, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.

Affected Software

Name Vendor Start Version End Version
E107 E107 * 0.7.20 (including)
E107 E107 0.6_10 (including) 0.6_10 (including)
E107 E107 0.6_11 (including) 0.6_11 (including)
E107 E107 0.6_12 (including) 0.6_12 (including)
E107 E107 0.6_13 (including) 0.6_13 (including)
E107 E107 0.6_14 (including) 0.6_14 (including)
E107 E107 0.6_15 (including) 0.6_15 (including)
E107 E107 0.6_15a (including) 0.6_15a (including)
E107 E107 0.7 (including) 0.7 (including)
E107 E107 0.7.0 (including) 0.7.0 (including)
E107 E107 0.7.1 (including) 0.7.1 (including)
E107 E107 0.7.2 (including) 0.7.2 (including)
E107 E107 0.7.3 (including) 0.7.3 (including)
E107 E107 0.7.4 (including) 0.7.4 (including)
E107 E107 0.7.5 (including) 0.7.5 (including)
E107 E107 0.7.6 (including) 0.7.6 (including)
E107 E107 0.7.7 (including) 0.7.7 (including)
E107 E107 0.7.8 (including) 0.7.8 (including)
E107 E107 0.7.9 (including) 0.7.9 (including)
E107 E107 0.7.10 (including) 0.7.10 (including)
E107 E107 0.7.11 (including) 0.7.11 (including)
E107 E107 0.7.12 (including) 0.7.12 (including)
E107 E107 0.7.13 (including) 0.7.13 (including)
E107 E107 0.7.14 (including) 0.7.14 (including)
E107 E107 0.7.15 (including) 0.7.15 (including)
E107 E107 0.7.16 (including) 0.7.16 (including)
E107 E107 0.7.17 (including) 0.7.17 (including)
E107 E107 0.7.18 (including) 0.7.18 (including)
E107 E107 0.7.19 (including) 0.7.19 (including)
E107 E107 0.545 (including) 0.545 (including)
E107 E107 0.547-beta (including) 0.547-beta (including)
E107 E107 0.548-beta (including) 0.548-beta (including)
E107 E107 0.549-beta (including) 0.549-beta (including)
E107 E107 0.551-beta (including) 0.551-beta (including)
E107 E107 0.552-beta (including) 0.552-beta (including)
E107 E107 0.553-beta (including) 0.553-beta (including)
E107 E107 0.554 (including) 0.554 (including)
E107 E107 0.554-beta (including) 0.554-beta (including)
E107 E107 0.555-beta (including) 0.555-beta (including)
E107 E107 0.600 (including) 0.600 (including)
E107 E107 0.601 (including) 0.601 (including)
E107 E107 0.602 (including) 0.602 (including)
E107 E107 0.603 (including) 0.603 (including)
E107 E107 0.604 (including) 0.604 (including)
E107 E107 0.605 (including) 0.605 (including)
E107 E107 0.606 (including) 0.606 (including)
E107 E107 0.607 (including) 0.607 (including)
E107 E107 0.608 (including) 0.608 (including)
E107 E107 0.609 (including) 0.609 (including)
E107 E107 0.610 (including) 0.610 (including)
E107 E107 0.611 (including) 0.611 (including)
E107 E107 0.612 (including) 0.612 (including)
E107 E107 0.613 (including) 0.613 (including)
E107 E107 0.614 (including) 0.614 (including)
E107 E107 0.615 (including) 0.615 (including)
E107 E107 0.615a (including) 0.615a (including)
E107 E107 0.616 (including) 0.616 (including)
E107 E107 0.617 (including) 0.617 (including)
E107 E107 0.6171 (including) 0.6171 (including)
E107 E107 0.6172 (including) 0.6172 (including)
E107 E107 0.6173 (including) 0.6173 (including)
E107 E107 0.6174 (including) 0.6174 (including)
E107 E107 0.6175 (including) 0.6175 (including)

References