Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
e107 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2008-4785
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
E107 Alternate Profiles Plugin
E107 Alternate Profiles Plugin 0.2
1 EDB exploit
10
CVSSv2
CVE-2008-1989
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the e107path parameter.
123flashchat 123 Flash Chat Module 6.8.0
E107 E107
1 EDB exploit
7.5
CVSSv2
CVE-2008-4786
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote malicious users to execute arbitrary SQL commands via the category_id parameter.
E107 Easyshop Plugin
1 EDB exploit
4.3
CVSSv2
CVE-2008-1702
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote malicious users to obtain sensitive information via a full pathname in the file parameter. NOTE: some of these details are obtained from third party information.
E107 My Gallery 2.3
1 EDB exploit
7.5
CVSSv2
CVE-2008-2455
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote malicious users to execute arbitrary SQL commands via the rid parameter.
E107coders E107 Blog Engine 2.2
1 EDB exploit
6.8
CVSSv2
CVE-2008-2020
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (...
My123tkshop E-commerce-suite 0.9.1
Phpmybittorrent Phpmybittorrent 1.2.2
Webze Webze 0.5.9
E107 E107 0.7.11
Labgab Labgab 1.1
Phpnuke Php-nuke 7.0
Torrentflux Project Torrentflux 2.3
Phpnuke Php-nuke 8.1
Opendb Opendb 1.5.0
7.5
CVSSv2
CVE-2008-6438
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote malicious users to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is a...
E107coders Macguru Blog Engine Plugin 2.2
4 EDB exploits
7.5
CVSSv2
CVE-2008-4906
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote malicious users to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.
W1n78 Lyrics 0.4.2
1 EDB exploit
7.5
CVSSv2
CVE-2008-6466
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote malicious users to execute arbitrary SQL commands via the image parameter in an image-detail action.
Akirapowered Image Gallery 0.9.6.2
1 EDB exploit
4.3
CVSSv2
CVE-2011-5186
Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote malicious users to inject arbitrary web script or HTML via the item_id parameter.
Burnsy Jbshop Plugin -
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »