Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
e107 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-4051
e107 0.6174 allows remote malicious users to vote multiple times for a download via repeated requests to rate.php.
E107 E107 0.6174
NA
CVE-2005-1966
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote malicious users to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.
E107 E107 1.0.1
NA
CVE-2006-5786
Directory traversal vulnerability in class2.php in e107 0.7.5 and previous versions allows remote malicious users to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.
E107 E107 0.7.5
1 EDB exploit
8.8
CVSSv3
CVE-2016-10753
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
E107 E107 2.1.2
7.2
CVSSv3
CVE-2016-10378
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
E107 E107 2.1.1
NA
CVE-2006-2590
SQL injection vulnerability in e107 prior to 0.7.5 allows remote malicious users to execute arbitrary SQL commands via unknown attack vectors.
E107 E107 0.7.5
NA
CVE-2006-2591
Unspecified vulnerability in e107 prior to 0.7.5 has unknown impact and remote attack vectors related to an "emailing exploit".
E107 E107 0.7.5
NA
CVE-2014-9459
Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2 allows remote malicious users to hijack the authentication of administrators for requests that add users to the administrator group via the id parameter in an ...
E107 E107 2.0
NA
CVE-2012-3843
Cross-site scripting (XSS) vulnerability in the registration page in e107, probably 1.0.1, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
E107 E107 1.0.1
NA
CVE-2008-6208
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 CMS 0.7.11 allows remote malicious users to inject arbitrary web script or HTML via the (1) author_name, (2) itemtitle, and (3) item parameters. NOTE: the provenance of this information is unknown; the details are...
E107 E107 0.7.11
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3661
open redirect
CVE-2024-25512
CVE-2024-33788
command injection
SSTI
CVE-2024-0043
CVE-2024-29210
CVE-2024-25510
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »