peter bassill · operator
$ cve CVE-2010-1077 JSON

CVE-2010-1077 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.86% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2010-03-23
Last modified2026-06-16

Affected (2)

VendorProduct
vbseovbseo
vbulletinvbulletin

Public exploits

SourceTitleDate
exploit-dbvBSEO 3.1.0 - Local File Inclusion2010-02-22

References

→ the Explorer  ·  watch your stack  ·  NVD