Security Advisory

CVE-2010-2099

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-05-27 22:00:00
Last updated 2024-09-17 04:19:20
Assigner mitre
State PUBLISHED

Description

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.