CVE-2016-10073

HIGH

Vanilla Forums <2.3.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2016-10073. PoCs published by Dawid Golunski, Jay Turla, Medz Barao, including Metasploit module auxiliary/scanner/http/host_header_injection.

AI-analyzed exploit summary This exploit leverages CVE-2016-10073 (Header Injection) and CVE-2016-10033 (RCE) in Vanilla Forums <= 2.3 to achieve unauthenticated remote code execution via crafted Host headers in password reset requests.

Description

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

Exploits (2)

exploitdb WORKING POC
by Dawid Golunski · bashremotephp
https://www.exploit-db.com/exploits/41996

This exploit leverages CVE-2016-10073 (Header Injection) and CVE-2016-10033 (RCE) in Vanilla Forums <= 2.3 to achieve unauthenticated remote code execution via crafted Host headers in password reset requests.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Vanilla Forums <= 2.3
No auth needed
Prerequisites: Target URL · Attacker-controlled server to host payload · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit SCANNER
by Jay Turla, Medz Barao · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/host_header_injection.rb

This Metasploit module scans for HTTP Host header injection vulnerabilities by sending requests with manipulated Host, X-Host, and X-Forwarded-Host headers and checking for their reflection in the response.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: HTTP servers with vulnerable Host header handling
No auth needed
Prerequisites: Network access to the target HTTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/142486/Vanilla-Forums-2.3-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41996/

Scores

CVSS v3 7.5
EPSS 0.8361
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
vanillaforums/vanilla < 2.3.0
Published May 23, 2017
Tracked Since Feb 18, 2026