Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
e107 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2011-4921
SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions prior to 1.0.0, allows remote malicious users to execute arbitrary SQL commands via the username parameter.
E107 E107 0.7.26
NA
CVE-2012-6433
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote malicious users to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.
E107 E107 1.0.1
1 EDB exploit
NA
CVE-2012-6434
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote malicious users to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) download_url, (2) download_url_extended, (3)...
E107 E107 1.0.2
1 EDB exploit
NA
CVE-2008-6208
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 CMS 0.7.11 allows remote malicious users to inject arbitrary web script or HTML via the (1) author_name, (2) itemtitle, and (3) item parameters. NOTE: the provenance of this information is unknown; the details are...
E107 E107 0.7.11
NA
CVE-2011-3731
e107 0.7.24 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by e107_plugins/pdf/e107pdf.php and certain other files.
E107 E107 0.7.24
NA
CVE-2005-4051
e107 0.6174 allows remote malicious users to vote multiple times for a download via repeated requests to rate.php.
E107 E107 0.6174
5.4
CVSSv3
CVE-2023-36121
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote malicious user to execute arbitrary code via the description function in the SEO project.
E107 E107 2.3.2
6.5
CVSSv3
CVE-2017-8098
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
E107 E107 2.1.4
7.2
CVSSv3
CVE-2016-10378
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
E107 E107 2.1.1
6.5
CVSSv3
CVE-2018-11127
e107 2.1.7 has CSRF resulting in arbitrary user deletion.
E107 E107 2.1.7
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »