CVE-2011-10018 Details
Description
myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.
A backdoor allowing arbitrary PHP code execution has been introduced in myBB version 1.6.4. This vulnerability arises from unauthorized code embedded in the source package, which was not part of the intended application logic. Exploitation is achieved by injecting payloads into a specially crafted collapsed cookie, requiring no authentication and leading to full compromise of the web server under the application's context.
Users are advised to manually download and install the latest version of myBB. Instructions for patching the vulnerability are available on the myBB blog.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mybb mybb | 1.6.4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | Initial Analysis | [email protected] |
| Aug 14, 2025 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | New CVE Received | [email protected] |