Show filters
77 Total Results
Displaying 11-20 of 77
Sort by:
Attacker Value
Unknown

CVE-2018-16381

Disclosure Date: September 05, 2018 (last updated November 27, 2024)
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
0
Attacker Value
Unknown

CVE-2018-15901

Disclosure Date: August 28, 2018 (last updated November 27, 2024)
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
0
Attacker Value
Unknown

CVE-2018-11127

Disclosure Date: May 15, 2018 (last updated November 26, 2024)
e107 2.1.7 has CSRF resulting in arbitrary user deletion.
0
Attacker Value
Unknown

CVE-2016-10378

Disclosure Date: May 29, 2017 (last updated November 26, 2024)
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
0
Attacker Value
Unknown

CVE-2017-8098

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
0
Attacker Value
Unknown

CVE-2015-1057

Disclosure Date: January 16, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.
0
Attacker Value
Unknown

CVE-2015-1041

Disclosure Date: January 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.
0
Attacker Value
Unknown

CVE-2014-9459

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2 allows remote attackers to hijack the authentication of administrators for requests that add users to the administrator group via the id parameter in an admin action.
0
Attacker Value
Unknown

CVE-2014-4734

Disclosure Date: July 21, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.
0
Attacker Value
Unknown

CVE-2013-7305

Disclosure Date: January 22, 2014 (last updated October 05, 2023)
fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user.
0