Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-2099
Description:bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.
Test IDs: 1.3.6.1.4.1.25623.1.0.100649  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-2099
BugTraq ID: 40252
http://www.securityfocus.com/bid/40252
http://php-security.org/2010/05/19/mops-2010-035-e107-bbcode-remote-php-code-execution-vulnerability/index.html




© 1998-2025 E-Soft Inc. All rights reserved.