Записи e107
91 опубликованных записей вендора e107.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
91 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2008-1989Proof of concept | PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, a123flashchat · 123 flash chat module · CWE-94 | Критическая10,0 | — | 3,6 % | 27 апр. 2008 г. |
36Наблюдать | CVE-2021-27885Proof of concept | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.e107 · e107 · CWE-352 | Высокая8,8 | — | 3,2 % | 2 мар. 2021 г. |
35Наблюдать | CVE-2016-10753Эксплойта нет | e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.e107 · e107 · CWE-502 | Высокая8,8 | — | 1,7 % | 24 мая 2019 г. |
35Наблюдать | CVE-2018-15901Эксплойта нет | e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.e107 · e107 · CWE-352 | Высокая8,8 | — | 0,6 % | 28 авг. 2018 г. |
34Наблюдать | CVE-2004-2262Proof of concept | ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary coe107 · e107 · CWE-434 | Высокая7,5 | — | 14,9 % | 31 дек. 2004 г. |
34Наблюдать | CVE-2022-50939Эксплойта нет | e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Overridee107 · e107 · CWE-22 | Высокая8,6 | — | 1,3 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2022-50907Эксплойта нет | e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCEe107 · e107 · CWE-434 | Высокая8,6 | — | 1,2 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2022-50916Эксплойта нет | e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file overridee107 · e107 · CWE-434 | Высокая8,7 | — | 0,9 % | 13 янв. 2026 г. |
32Наблюдать | CVE-2011-1513Proof of concept | Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not ree107 · e107 · CWE-78 | Высокая7,5 | — | 5,6 % | 4 нояб. 2011 г. |
31Наблюдать | CVE-2010-2099Proof of concept | bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which e107 · e107 · CWE-264 | Высокая7,5 | — | 4,9 % | 27 мая 2010 г. |
31Наблюдать | CVE-2008-6438Proof of concept | SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe107 · e107 · CWE-89 | Высокая7,5 | — | 3,4 % | 6 мар. 2009 г. |
31Наблюдать | CVE-2006-5786Proof of concept | Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary e107 · e107 | Высокая7,5 | — | 2,5 % | 7 нояб. 2006 г. |
31Наблюдать | CVE-2005-2559Эксплойта нет | doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shee107 · e107 | Высокая7,5 | — | 2,3 % | 16 авг. 2005 г. |
31Наблюдать | CVE-2005-1949Эксплойта нет | The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands viae107 · e107 | Высокая7,5 | — | 2,1 % | 16 июн. 2005 г. |
31Наблюдать | CVE-2004-2041Эксплойта нет | PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modie107 · e107 | Высокая7,5 | — | 2,1 % | 29 мая 2004 г. |
31Наблюдать | CVE-2004-2042Эксплойта нет | Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via e107 · e107 | Высокая7,5 | — | 1,9 % | 29 мая 2004 г. |
31Наблюдать | CVE-2005-1966Эксплойта нет | The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharactere107 · e107 | Высокая7,5 | — | 1,8 % | 10 июн. 2005 г. |
31Наблюдать | CVE-2005-4224Эксплойта нет | Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the eme107 · e107 | Высокая7,5 | — | 1,7 % | 14 дек. 2005 г. |
31Наблюдать | CVE-2006-4548Эксплойта нет | e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumere107 · e107 | Высокая7,5 | — | 1,7 % | 5 сент. 2006 г. |
31Наблюдать | CVE-2008-2020Эксплойта нет | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) my123tkshop · e-commerce-suite · CWE-330 | Высокая7,5 | — | 1,7 % | 29 апр. 2008 г. |
30Наблюдать | CVE-2005-3521Эксплойта нет | SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass e107 · e107 | Высокая7,5 | — | 1,6 % | 6 нояб. 2005 г. |
30Наблюдать | CVE-2008-4906Proof of concept | SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrarye107 · e107 · CWE-89 | Высокая7,5 | — | 1,1 % | 3 нояб. 2008 г. |
30Наблюдать | CVE-2008-6114Proof of concept | SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitmytipper · zogo shop · CWE-89 | Высокая7,5 | — | 1,1 % | 11 февр. 2009 г. |
30Наблюдать | CVE-2009-4084Эксплойта нет | SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via ue107 · e107 · CWE-89 | Высокая7,5 | — | 1,1 % | 29 нояб. 2009 г. |
30Наблюдать | CVE-2010-2098Эксплойта нет | Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks ve107 · e107 | Высокая7,5 | — | 1,1 % | 27 мая 2010 г. |
- CVE-2008-198941В плане
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, a
КритическаяCVSS 10,0Proof of conceptEPSS 4 %123flashchat · 123 flash chat module27 апр. 2008 г.
- CVE-2021-2788536Наблюдать
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %e107 · e1072 мар. 2021 г.
- CVE-2016-1075335Наблюдать
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %e107 · e10724 мая 2019 г.
- CVE-2018-1590135Наблюдать
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %e107 · e10728 авг. 2018 г.
- CVE-2004-226234Наблюдать
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary co
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %e107 · e10731 дек. 2004 г.
- CVE-2022-5093934Наблюдать
e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %e107 · e10713 янв. 2026 г.
- CVE-2022-5090734Наблюдать
e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %e107 · e10713 янв. 2026 г.
- CVE-2022-5091634Наблюдать
e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %e107 · e10713 янв. 2026 г.
- CVE-2011-151332Наблюдать
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not re
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %e107 · e1074 нояб. 2011 г.
- CVE-2010-209931Наблюдать
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %e107 · e10727 мая 2010 г.
- CVE-2008-643831Наблюдать
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to ex
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %e107 · e1076 мар. 2009 г.
- CVE-2006-578631Наблюдать
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %e107 · e1077 нояб. 2006 г.
- CVE-2005-255931Наблюдать
doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) she
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e10716 авг. 2005 г.
- CVE-2005-194931Наблюдать
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e10716 июн. 2005 г.
- CVE-2004-204131Наблюдать
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e10729 мая 2004 г.
- CVE-2004-204231Наблюдать
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e10729 мая 2004 г.
- CVE-2005-196631Наблюдать
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacter
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e10710 июн. 2005 г.
- CVE-2005-422431Наблюдать
Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the em
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e10714 дек. 2005 г.
- CVE-2006-454831Наблюдать
e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumer
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e1075 сент. 2006 г.
- CVE-2008-202031Наблюдать
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %my123tkshop · e-commerce-suite29 апр. 2008 г.
- CVE-2005-352130Наблюдать
SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %e107 · e1076 нояб. 2005 г.
- CVE-2008-490630Наблюдать
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %e107 · e1073 нояб. 2008 г.
- CVE-2008-611430Наблюдать
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbit
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %mytipper · zogo shop11 февр. 2009 г.
- CVE-2009-408430Наблюдать
SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via u
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %e107 · e10729 нояб. 2009 г.
- CVE-2010-209830Наблюдать
Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks v
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %e107 · e10727 мая 2010 г.