peter bassill · operator
$ cve CVE-2010-2099 JSON

CVE-2010-2099 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 4.9% (pctl 92)

Patch early

A public exploit exists.

Description

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS4.87% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2010-05-27
Last modified2026-06-16

Affected (1)

VendorProduct
e107e107

Public exploits

SourceTitleDate
exploit-dbe107 - Code Exection2010-05-24

References

→ the Explorer  ·  watch your stack  ·  NVD