216.73.217.22

CVE-2011-10018

· Published 13/08/2025 21:15 · Modified 13/08/2025 21:15

Labels: CVE-2011-10018 2025-08-13CVE-2011-10018CWE-94[email protected]

Essential information

Published
13/08/2025 21:15
Modified
13/08/2025 21:15
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mybb / mybb cpe:2.3:a:mybb:mybb:1.6.4:*:*:*:*:*:*:*

References