İçeriğe atla
Noroxi

e107 kayıtları

e107 üreticisine ait 91 yayımlanmış kayıt.

Tüm kayıtlar

91 kayıt
  • CVE-2008-1989
    41Planlayın

    PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, a

    KritikCVSS 10,0Kavram kanıtıEPSS %4

    123flashchat · 123 flash chat module27 Nis 2008

  • CVE-2021-27885
    36İzleyin

    usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    e107 · e1072 Mar 2021

  • CVE-2016-10753
    35İzleyin

    e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

    YüksekCVSS 8,8İstismar yokEPSS %2

    e107 · e10724 May 2019

  • CVE-2018-15901
    35İzleyin

    e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

    YüksekCVSS 8,8İstismar yokEPSS %1

    e107 · e10728 Ağu 2018

  • CVE-2004-2262
    34İzleyin

    ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary co

    YüksekCVSS 7,5Kavram kanıtıEPSS %15

    e107 · e10731 Ara 2004

  • CVE-2022-50939
    34İzleyin

    e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override

    YüksekCVSS 8,6İstismar yokEPSS %1

    e107 · e10713 Oca 2026

  • CVE-2022-50907
    34İzleyin

    e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE

    YüksekCVSS 8,6İstismar yokEPSS %1

    e107 · e10713 Oca 2026

  • CVE-2022-50916
    34İzleyin

    e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override

    YüksekCVSS 8,7İstismar yokEPSS %1

    e107 · e10713 Oca 2026

  • CVE-2011-1513
    32İzleyin

    Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not re

    YüksekCVSS 7,5Kavram kanıtıEPSS %6

    e107 · e1074 Kas 2011

  • CVE-2010-2099
    31İzleyin

    bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    e107 · e10727 May 2010

  • CVE-2008-6438
    31İzleyin

    SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to ex

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    e107 · e1076 Mar 2009

  • CVE-2006-5786
    31İzleyin

    Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    e107 · e1077 Kas 2006

  • CVE-2005-2559
    31İzleyin

    doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) she

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e10716 Ağu 2005

  • CVE-2005-1949
    31İzleyin

    The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e10716 Haz 2005

  • CVE-2004-2041
    31İzleyin

    PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modi

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e10729 May 2004

  • CVE-2004-2042
    31İzleyin

    Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e10729 May 2004

  • CVE-2005-1966
    31İzleyin

    The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacter

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e10710 Haz 2005

  • CVE-2005-4224
    31İzleyin

    Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the em

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e10714 Ara 2005

  • CVE-2006-4548
    31İzleyin

    e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumer

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e1075 Eyl 2006

  • CVE-2008-2020
    31İzleyin

    The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)

    YüksekCVSS 7,5İstismar yokEPSS %2

    my123tkshop · e-commerce-suite29 Nis 2008

  • CVE-2005-3521
    30İzleyin

    SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass

    YüksekCVSS 7,5İstismar yokEPSS %2

    e107 · e1076 Kas 2005

  • CVE-2008-4906
    30İzleyin

    SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    e107 · e1073 Kas 2008

  • CVE-2008-6114
    30İzleyin

    SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbit

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    mytipper · zogo shop11 Şub 2009

  • CVE-2009-4084
    30İzleyin

    SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via u

    YüksekCVSS 7,5İstismar yokEPSS %1

    e107 · e10729 Kas 2009

  • CVE-2010-2098
    30İzleyin

    Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks v

    YüksekCVSS 7,5İstismar yokEPSS %1

    e107 · e10727 May 2010