CVE-2011-10018
myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 53.00%
- CWE
- CWE-912, CWE-94
- Published
- 2025-08-13
- Last modified
- 2026-04-07
Affected products
- myBB Group Forum Software
Weakness type
Related vulnerabilities
- CVE-2024-20439 — A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
- CVE-2010-20103 — ProFTPD 1.3.3c Backdoor Command Execution
- CVE-2025-34117 — Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
- CVE-2026-3587 — Hidden CLI Function Allows Root Access
- CVE-2024-39754 — A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte
- CVE-2024-45697 — D-Link WiFi router - Hidden Functionality
- CVE-2020-12504 — Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2022-3203 — ORing net IAP-420(+) Hidden Functionality