e107 kayıtları
e107 üreticisine ait 91 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 26
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
91 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2008-1989Kavram kanıtı | PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, a123flashchat · 123 flash chat module · CWE-94 | Kritik10,0 | — | %3,6 | 27 Nis 2008 |
36İzleyin | CVE-2021-27885Kavram kanıtı | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.e107 · e107 · CWE-352 | Yüksek8,8 | — | %3,2 | 2 Mar 2021 |
35İzleyin | CVE-2016-10753İstismar yok | e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.e107 · e107 · CWE-502 | Yüksek8,8 | — | %1,7 | 24 May 2019 |
35İzleyin | CVE-2018-15901İstismar yok | e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.e107 · e107 · CWE-352 | Yüksek8,8 | — | %0,6 | 28 Ağu 2018 |
34İzleyin | CVE-2004-2262Kavram kanıtı | ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary coe107 · e107 · CWE-434 | Yüksek7,5 | — | %14,9 | 31 Ara 2004 |
34İzleyin | CVE-2022-50939İstismar yok | e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Overridee107 · e107 · CWE-22 | Yüksek8,6 | — | %1,3 | 13 Oca 2026 |
34İzleyin | CVE-2022-50907İstismar yok | e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCEe107 · e107 · CWE-434 | Yüksek8,6 | — | %1,2 | 13 Oca 2026 |
34İzleyin | CVE-2022-50916İstismar yok | e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file overridee107 · e107 · CWE-434 | Yüksek8,7 | — | %0,9 | 13 Oca 2026 |
32İzleyin | CVE-2011-1513Kavram kanıtı | Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not ree107 · e107 · CWE-78 | Yüksek7,5 | — | %5,6 | 4 Kas 2011 |
31İzleyin | CVE-2010-2099Kavram kanıtı | bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which e107 · e107 · CWE-264 | Yüksek7,5 | — | %4,9 | 27 May 2010 |
31İzleyin | CVE-2008-6438Kavram kanıtı | SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe107 · e107 · CWE-89 | Yüksek7,5 | — | %3,4 | 6 Mar 2009 |
31İzleyin | CVE-2006-5786Kavram kanıtı | Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary e107 · e107 | Yüksek7,5 | — | %2,5 | 7 Kas 2006 |
31İzleyin | CVE-2005-2559İstismar yok | doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shee107 · e107 | Yüksek7,5 | — | %2,3 | 16 Ağu 2005 |
31İzleyin | CVE-2005-1949İstismar yok | The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands viae107 · e107 | Yüksek7,5 | — | %2,1 | 16 Haz 2005 |
31İzleyin | CVE-2004-2041İstismar yok | PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modie107 · e107 | Yüksek7,5 | — | %2,1 | 29 May 2004 |
31İzleyin | CVE-2004-2042İstismar yok | Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via e107 · e107 | Yüksek7,5 | — | %1,9 | 29 May 2004 |
31İzleyin | CVE-2005-1966İstismar yok | The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharactere107 · e107 | Yüksek7,5 | — | %1,8 | 10 Haz 2005 |
31İzleyin | CVE-2005-4224İstismar yok | Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the eme107 · e107 | Yüksek7,5 | — | %1,7 | 14 Ara 2005 |
31İzleyin | CVE-2006-4548İstismar yok | e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumere107 · e107 | Yüksek7,5 | — | %1,7 | 5 Eyl 2006 |
31İzleyin | CVE-2008-2020İstismar yok | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) my123tkshop · e-commerce-suite · CWE-330 | Yüksek7,5 | — | %1,7 | 29 Nis 2008 |
30İzleyin | CVE-2005-3521İstismar yok | SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass e107 · e107 | Yüksek7,5 | — | %1,6 | 6 Kas 2005 |
30İzleyin | CVE-2008-4906Kavram kanıtı | SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrarye107 · e107 · CWE-89 | Yüksek7,5 | — | %1,1 | 3 Kas 2008 |
30İzleyin | CVE-2008-6114Kavram kanıtı | SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitmytipper · zogo shop · CWE-89 | Yüksek7,5 | — | %1,1 | 11 Şub 2009 |
30İzleyin | CVE-2009-4084İstismar yok | SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via ue107 · e107 · CWE-89 | Yüksek7,5 | — | %1,1 | 29 Kas 2009 |
30İzleyin | CVE-2010-2098İstismar yok | Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks ve107 · e107 | Yüksek7,5 | — | %1,1 | 27 May 2010 |
- CVE-2008-198941Planlayın
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, a
KritikCVSS 10,0Kavram kanıtıEPSS %4123flashchat · 123 flash chat module27 Nis 2008
- CVE-2021-2788536İzleyin
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
YüksekCVSS 8,8Kavram kanıtıEPSS %3e107 · e1072 Mar 2021
- CVE-2016-1075335İzleyin
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
YüksekCVSS 8,8İstismar yokEPSS %2e107 · e10724 May 2019
- CVE-2018-1590135İzleyin
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
YüksekCVSS 8,8İstismar yokEPSS %1e107 · e10728 Ağu 2018
- CVE-2004-226234İzleyin
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary co
YüksekCVSS 7,5Kavram kanıtıEPSS %15e107 · e10731 Ara 2004
- CVE-2022-5093934İzleyin
e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override
YüksekCVSS 8,6İstismar yokEPSS %1e107 · e10713 Oca 2026
- CVE-2022-5090734İzleyin
e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE
YüksekCVSS 8,6İstismar yokEPSS %1e107 · e10713 Oca 2026
- CVE-2022-5091634İzleyin
e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override
YüksekCVSS 8,7İstismar yokEPSS %1e107 · e10713 Oca 2026
- CVE-2011-151332İzleyin
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not re
YüksekCVSS 7,5Kavram kanıtıEPSS %6e107 · e1074 Kas 2011
- CVE-2010-209931İzleyin
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which
YüksekCVSS 7,5Kavram kanıtıEPSS %5e107 · e10727 May 2010
- CVE-2008-643831İzleyin
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to ex
YüksekCVSS 7,5Kavram kanıtıEPSS %3e107 · e1076 Mar 2009
- CVE-2006-578631İzleyin
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %2e107 · e1077 Kas 2006
- CVE-2005-255931İzleyin
doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) she
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e10716 Ağu 2005
- CVE-2005-194931İzleyin
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e10716 Haz 2005
- CVE-2004-204131İzleyin
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modi
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e10729 May 2004
- CVE-2004-204231İzleyin
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e10729 May 2004
- CVE-2005-196631İzleyin
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacter
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e10710 Haz 2005
- CVE-2005-422431İzleyin
Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the em
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e10714 Ara 2005
- CVE-2006-454831İzleyin
e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumer
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e1075 Eyl 2006
- CVE-2008-202031İzleyin
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)
YüksekCVSS 7,5İstismar yokEPSS %2my123tkshop · e-commerce-suite29 Nis 2008
- CVE-2005-352130İzleyin
SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass
YüksekCVSS 7,5İstismar yokEPSS %2e107 · e1076 Kas 2005
- CVE-2008-490630İzleyin
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %1e107 · e1073 Kas 2008
- CVE-2008-611430İzleyin
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbit
YüksekCVSS 7,5Kavram kanıtıEPSS %1mytipper · zogo shop11 Şub 2009
- CVE-2009-408430İzleyin
SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via u
YüksekCVSS 7,5İstismar yokEPSS %1e107 · e10729 Kas 2009
- CVE-2010-209830İzleyin
Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks v
YüksekCVSS 7,5İstismar yokEPSS %1e107 · e10727 May 2010