Advertisement






e107 contact.php Arbitrary PHP Command Execution

CVE Category Price Severity
CVE-2018-9023 CWE-78 $700 Medium
Author Risk Exploitation Type Date
Unknown High Remote 2010-07-20
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.231 0.791

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2010070104

Below is a copy:

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.

hackers also can upload php shell scripts or deface a webpage.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum