CVE-2010-1337 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.29% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-04-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| lussumo | vanilla |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Lussumo Vanilla 1.1.10 - 'definitions.php' Multiple Remote File Inclusions | 2010-03-23 |
References
- http://www.packetstormsecurity.com/1003-exploits/vanilla-rfi.txt
- http://www.securityfocus.com/bid/38889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57147
- http://www.packetstormsecurity.com/1003-exploits/vanilla-rfi.txt
- http://www.securityfocus.com/bid/38889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57147
→ the Explorer · watch your stack · NVD