Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2013-7305
Disclosure Date: January 22, 2014 (last updated October 05, 2023)
fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user.
0
Attacker Value
Unknown
CVE-2013-2750
Disclosure Date: January 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string.
0
Attacker Value
Unknown
CVE-2012-6433
Disclosure Date: January 03, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.
0
Attacker Value
Unknown
CVE-2012-3843
Disclosure Date: July 03, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the registration page in e107, probably 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-1409
Disclosure Date: April 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.
0
Attacker Value
Unknown
CVE-2005-1966
Disclosure Date: June 10, 2005 (last updated February 22, 2025)
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.
0