Show filters
77 Total Results
Displaying 71-77 of 77
Sort by:
Attacker Value
Unknown
CVE-2004-2262
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
0
Attacker Value
Unknown
CVE-2004-2042
Disclosure Date: May 29, 2004 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.
0
Attacker Value
Unknown
CVE-2004-2040
Disclosure Date: May 29, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.
0
Attacker Value
Unknown
CVE-2004-2039
Disclosure Date: May 29, 2004 (last updated February 22, 2025)
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.
0
Attacker Value
Unknown
CVE-2004-2028
Disclosure Date: May 21, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.
0
Attacker Value
Unknown
CVE-2004-2031
Disclosure Date: May 21, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.
0
Attacker Value
Unknown
CVE-2003-1191
Disclosure Date: October 29, 2003 (last updated February 22, 2025)
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.
0