← back
CVE-2010-2099observed exploitation

CVE-2010-2099

45Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 4.9%
from disclosure to weapon0 days
Published on NVDMay 27
1st PoCMay 24
VulnCheck+84d
exploitation probability
4.9%top 9% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.