CVE-2011-10018 describes a critical backdoor in myBB version 1.6.4, allowing remote attackers to execute arbitrary PHP code. This vulnerability, introduced during packaging, leverages specially crafted collapsed cookies and requires no authentication. With a CVSS score of 9.8, it poses a severe risk, enabling full web server compromise under the web application's context. While not on the KEV catalog, a Metasploit module exists, and community discussion indicates awareness of this high-impact flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.4CPE matchmatch criteria | cpe:2.3:a:mybb:mybb:1.6.4:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.