4.3
CVSSv2

CVE-2004-2040

Published: 29/05/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote malicious users to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.

Vulnerable Product Search on Vulmon Subscribe to Product

e107 e107 0.6_15a

e107 e107 0.6_15

Exploits

source: wwwsecurityfocuscom/bid/10436/info e107 is prone to multiple cross-site scripting, HTML injection, file inclusion, and SQL injection vulnerabilities This may compromise various security properties of a Web site running the software, including allowing remote attackers to execute malicious PHP code - HTML injection in the "ema ...
source: wwwsecurityfocuscom/bid/10436/info e107 is prone to multiple cross-site scripting, HTML injection, file inclusion, and SQL injection vulnerabilities This may compromise various security properties of a Web site running the software, including allowing remote attackers to execute malicious PHP code wwwexamplecom/e107_0 ...