myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mybb
Mybb mybb |
|
CPEs | cpe:2.3:a:mybb:mybb:1.6.4:*:*:*:*:*:*:* | |
Vendors & Products |
Mybb
Mybb mybb |
|
Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application. | |
Title | myBB 1.6.4 Backdoor Arbitrary Command Execution | |
Weaknesses | CWE-912 CWE-94 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-13T20:35:31.755Z
Updated: 2025-08-14T14:08:01.308Z
Reserved: 2025-08-13T17:52:08.905Z
Link: CVE-2011-10018

Updated: 2025-08-14T14:07:45.471Z

Status : Analyzed
Published: 2025-08-13T21:15:29.387
Modified: 2025-08-14T17:42:18.333
Link: CVE-2011-10018

No data.