Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2009-1409

Disclosure Date: April 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.
0
Attacker Value
Unknown

CVE-2008-5320

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.
0
Attacker Value
Unknown

CVE-2006-4757

Disclosure Date: September 13, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."
0
Attacker Value
Unknown

CVE-2006-3259

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment).
0
Attacker Value
Unknown

CVE-2006-0682

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2005-2327

Disclosure Date: July 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.
0