CVE-2011-10018

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb:1.6.4:*:*:*:*:*:*:*

History

14 Aug 2025, 17:42

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:mybb:mybb:1.6.4:*:*:*:*:*:*:*
First Time Mybb mybb
Mybb
References () https://blog.mybb.com/2011/10/06/1-6-4-security-vulnerabilit/ - () https://blog.mybb.com/2011/10/06/1-6-4-security-vulnerabilit/ - Vendor Advisory
References () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/mybb_backdoor.rb - () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/mybb_backdoor.rb - Product
References () https://web.archive.org/web/20111015224948/http://secunia.com/advisories/46300/ - () https://web.archive.org/web/20111015224948/http://secunia.com/advisories/46300/ - Third Party Advisory
References () https://www.exploit-db.com/exploits/17949 - () https://www.exploit-db.com/exploits/17949 - Exploit
References () https://www.vulncheck.com/advisories/mybb-backdoor-arbitrary-command-execution - () https://www.vulncheck.com/advisories/mybb-backdoor-arbitrary-command-execution - Third Party Advisory

14 Aug 2025, 14:15

Type Values Removed Values Added
References () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/mybb_backdoor.rb - () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/mybb_backdoor.rb -
References () https://www.exploit-db.com/exploits/17949 - () https://www.exploit-db.com/exploits/17949 -

14 Aug 2025, 13:11

Type Values Removed Values Added
Summary
  • (es) La versión 1.6.4 de myBB se distribuyó con una puerta trasera no autorizada incrustada en el código fuente. Esta puerta trasera permitía a atacantes remotos ejecutar código PHP arbitrario inyectando payloads en una cookie colapsada especialmente manipulada. Esta vulnerabilidad se introdujo durante el empaquetado y no formaba parte de la lógica de la aplicación. Su explotación no requiere autenticación y compromete por completo el servidor web en el contexto de la aplicación web.

13 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 21:15

Updated : 2025-08-14 17:42


NVD link : CVE-2011-10018

Mitre link : CVE-2011-10018

CVE.ORG link : CVE-2011-10018


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-912

Hidden Functionality