Blog | G5 Cyber Security

Vanilla Forums <= 2.3 Unauth. Remote Code Execution (RCE) exploit CVE-2016-10033 [0day]

Vanilla Forums software (including the latest stable version of 2.3 in its default configuration) is affected by: Remote Code Execution CVE-2016-10033 (0day) which can be exploited by unauthenticated remote attackers to execute arbitrary code and fully compromise the target application. The official stable version 2.2.3 available at: https://open.vanillaforums.com/addon/vanilla-core-2.1. Vanilla forums software is used by top brands to engage customers, drive loyalty and reduce support costs.”]

Source: https://exploitbox.io/vuln/Vanilla-Forums-Exploit-RCE-0day-Remote-Code-Exec-CVE-2016-10033.html

Exit mobile version