Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
e107 e107 vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2005-4224
Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote malicious users to execute arbitrary SQL commands via (1) the email, hideemail, image, realname, signature, timezone, and xupexist parameters in signup.php, (2) the content_comment, conten...
E107 E107 0.7
668
VMScore
CVE-2005-3521
SQL injection vulnerability in resetcore.php in e107 0.617 up to and including 0.6173 allows remote malicious users to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.
E107 E107 0.6172
E107 E107 0.617
E107 E107 0.6171
668
VMScore
CVE-2005-2559
doping.php in ePing plugin 1.02 and previous versions for e107 portal allows remote malicious users to execute arbitrary code or overwrite files via (1) shell metacharacters in the eping_count parameter or (2) restricted shell metacharacters such as ">" and "&am...
E107 E107
668
VMScore
CVE-2005-1949
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote malicious users to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.
E107 E107
668
VMScore
CVE-2005-1966
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote malicious users to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.
E107 E107 1.0.1
668
VMScore
CVE-2004-2042
Multiple SQL injection vulnerabilities in e107 0.615 allow remote malicious users to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.
E107 E107 0.615a
E107 E107 0.615
668
VMScore
CVE-2004-2041
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote malicious users to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.
655
VMScore
CVE-2008-5320
SQL injection vulnerability in usersettings.php in e107 0.7.13 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.
E107 E107 0.551 Beta
E107 E107 0.6175
E107 E107 0.616
E107 E107 0.7.10
E107 E107 0.6174
E107 E107 5.05
E107 E107 0.549 Beta
E107 E107 0.615a
E107 E107 0.7.7
E107 E107 5.21
E107 E107 0.7.4
E107 E107 0.555 Beta
E107 E107 0.6173
E107 E107 0.610
E107 E107 0.7.5
E107 E107 0.607
E107 E107 0.7.2
E107 E107 0.609
E107 E107 0.7.11
E107 E107 5.4 Beta6
E107 E107 0.606
E107 E107 0.602
1 EDB exploit
605
VMScore
CVE-2021-27885
usersettings.php in e107 up to and including 2.3.0 lacks a certain e_TOKEN protection mechanism.
E107 E107
605
VMScore
CVE-2018-15901
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
E107 E107 2.1.8
1 Github repository
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »