Перейти к содержимому
Noroxi

Записи e107

91 опубликованных записей вендора e107.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
26
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

91 записей
  • CVE-2008-1989
    41В плане

    PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, a

    КритическаяCVSS 10,0Proof of conceptEPSS 4 %

    123flashchat · 123 flash chat module27 апр. 2008 г.

  • CVE-2021-27885
    36Наблюдать

    usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    e107 · e1072 мар. 2021 г.

  • CVE-2016-10753
    35Наблюдать

    e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    e107 · e10724 мая 2019 г.

  • CVE-2018-15901
    35Наблюдать

    e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    e107 · e10728 авг. 2018 г.

  • CVE-2004-2262
    34Наблюдать

    ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary co

    ВысокаяCVSS 7,5Proof of conceptEPSS 15 %

    e107 · e10731 дек. 2004 г.

  • CVE-2022-50939
    34Наблюдать

    e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    e107 · e10713 янв. 2026 г.

  • CVE-2022-50907
    34Наблюдать

    e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    e107 · e10713 янв. 2026 г.

  • CVE-2022-50916
    34Наблюдать

    e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    e107 · e10713 янв. 2026 г.

  • CVE-2011-1513
    32Наблюдать

    Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not re

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    e107 · e1074 нояб. 2011 г.

  • CVE-2010-2099
    31Наблюдать

    bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    e107 · e10727 мая 2010 г.

  • CVE-2008-6438
    31Наблюдать

    SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to ex

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    e107 · e1076 мар. 2009 г.

  • CVE-2006-5786
    31Наблюдать

    Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    e107 · e1077 нояб. 2006 г.

  • CVE-2005-2559
    31Наблюдать

    doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) she

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e10716 авг. 2005 г.

  • CVE-2005-1949
    31Наблюдать

    The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e10716 июн. 2005 г.

  • CVE-2004-2041
    31Наблюдать

    PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e10729 мая 2004 г.

  • CVE-2004-2042
    31Наблюдать

    Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e10729 мая 2004 г.

  • CVE-2005-1966
    31Наблюдать

    The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacter

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e10710 июн. 2005 г.

  • CVE-2005-4224
    31Наблюдать

    Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the em

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e10714 дек. 2005 г.

  • CVE-2006-4548
    31Наблюдать

    e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumer

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e1075 сент. 2006 г.

  • CVE-2008-2020
    31Наблюдать

    The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    my123tkshop · e-commerce-suite29 апр. 2008 г.

  • CVE-2005-3521
    30Наблюдать

    SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    e107 · e1076 нояб. 2005 г.

  • CVE-2008-4906
    30Наблюдать

    SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    e107 · e1073 нояб. 2008 г.

  • CVE-2008-6114
    30Наблюдать

    SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbit

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    mytipper · zogo shop11 февр. 2009 г.

  • CVE-2009-4084
    30Наблюдать

    SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via u

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    e107 · e10729 нояб. 2009 г.

  • CVE-2010-2098
    30Наблюдать

    Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks v

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    e107 · e10727 мая 2010 г.