Show filters
77 Total Results
Displaying 1-10 of 77
Sort by:
Attacker Value
Unknown

CVE-2023-43874

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.
Attacker Value
Unknown

CVE-2023-43873

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.
Attacker Value
Unknown

CVE-2023-36121

Disclosure Date: August 02, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
Attacker Value
Unknown

CVE-2021-27885

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
Attacker Value
Unknown

CVE-2018-11734

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
In e107 v2.1.7, output without filtering results in XSS.
0
Attacker Value
Unknown

CVE-2018-17423

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
0
Attacker Value
Unknown

CVE-2016-10753

Disclosure Date: May 24, 2019 (last updated November 27, 2024)
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
0
Attacker Value
Unknown

CVE-2018-17081

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
0
Attacker Value
Unknown

CVE-2018-16389

Disclosure Date: September 12, 2018 (last updated November 27, 2024)
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
0
Attacker Value
Unknown

CVE-2018-16388

Disclosure Date: September 12, 2018 (last updated November 27, 2024)
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.
0