This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
Summuary | |
---|---|
CPE Name | cpe:/a:e107:e107:0.7.10 |
Detail | |||
---|---|---|---|
Vendor | e107 | First view | 2008-12-03 |
Product | e107 | Last view | 2014-07-21 |
Version | 0.7.10 | Type | Application |
Edition | |||
Language | |||
Update | |||
CPE Product | cpe:/a:e107:e107 |
Activity : Overall
Related : CVE
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
4.3 | 2014-07-21 | CVE-2014-4734 | Network | Medium | None Requ... | |
4.3 | 2014-01-22 | CVE-2013-7305 | Network | Medium | None Requ... | |
4.3 | 2014-01-22 | CVE-2013-2750 | Network | Medium | None Requ... | |
6.8 | 2012-08-31 | CVE-2011-4947 | Network | Medium | None Requ... | |
6.8 | 2012-08-31 | CVE-2011-4946 | Network | Medium | None Requ... | |
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
6 | 2012-02-14 | CVE-2010-5084 | Network | Medium | Requires ... | |
7.5 | 2011-11-04 | CVE-2011-1513 | Network | Low | None Requ... | |
4.3 | 2011-03-15 | CVE-2011-0457 | Network | Medium | None Requ... | |
4.3 | 2011-03-15 | CVE-2010-4757 | Network | Medium | None Requ... | |
7.5 | 2010-05-27 | CVE-2010-2099 | Network | Low | None Requ... | |
7.5 | 2010-05-27 | CVE-2010-2098 | Network | Low | None Requ... | |
3.5 | 2010-04-20 | CVE-2010-0997 | Network | Medium | Requires ... | |
6 | 2010-04-20 | CVE-2010-0996 | Network | Medium | Requires ... | |
7.5 | 2009-11-29 | CVE-2009-4084 | Network | Low | None Requ... | |
4.3 | 2009-11-29 | CVE-2009-4083 | Network | Medium | None Requ... | |
4.3 | 2009-09-28 | CVE-2009-3444 | Network | Medium | None Requ... | |
5.1 | 2009-04-24 | CVE-2009-1409 | Network | High | None Requ... | |
6.5 | 2008-12-03 | CVE-2008-5320 | Network | Low | Requires ... |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
43% (7) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
25% (4) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
12% (2) | CWE-352 | Cross-Site Request Forgery (CSRF) |
6% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
6% (1) | CWE-255 | Credentials Management |
% | id | Name |
---|---|---|
6% (1) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
77042 | e107 CMS install_.php MySQL Server Name Parsing Remote PHP Code Execution |
67367 | e107 submitnews.php submitnews_title Parameter XSS |
65243 | e107 bbcode/php.bb Access Control Check Weakness Arbitrary PHP Code Execution |
65056 | e107 usersettings.php loginname Parameter Blacklist Weakness SQL Injection |
63911 | e107 e107_plugins/content/content_manager.php content_heading Parameter XSS |
id | Description |
---|---|
63910 | e107 Crafted .php.filetypesphp Image File Upload Arbitrary PHP Code Execution |
60829 | e107 e107_admin/mailout.php Unspecified Parameter XSS |
60828 | e107 e107_admin/links.php Unspecified Parameter XSS |
60827 | e107 e107_admin/frontpage.php Unspecified Parameter XSS |
60826 | e107 e107_admin/users_extended.php Unspecified Parameter XSS |
60825 | e107 e107_admin/download.php Unspecified Parameter XSS |
60824 | e107 e107_admin/cpage.php Unspecified Parameter XSS |
60823 | e107 e107_admin/banner.php Unspecified Parameter XSS |
60822 | e107 e107_admin/banlist.php Unspecified Parameter XSS |
60821 | e107 e107_admin/newpost.php Unspecified Parameter XSS |
60820 | e107 e107_admin/usersettings.php Unspecified Parameter XSS |
60819 | e107 e107_admin/submitnews.php Unspecified Parameter XSS |
60608 | e107 Search Feature Unspecified SQL Injection |
58363 | e107 email.php HTTP Referer Header XSS |
53812 | e107 usersettings.php hide Parameter SQL Injection |
49207 | e107 usersettings.php ue[] Array Parameter SQL Injection |
OpenVAS Exploits
id | Description |
---|---|
2010-05-25 | Name : e107 BBCode Arbitrary PHP Code Execution Vulnerability File : nvt/gb_e107_40252.nasl |
2010-05-04 | Name : FreeBSD Ports: e107 File : nvt/freebsd_e107.nasl |
2009-10-08 | Name : e107 'Referer' Header Cross-Site Scripting Vulnerability File : nvt/gb_e107_referer_xss_vuln.nasl |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2013-05-13 | Name : The remote web server hosts a PHP script that is affected by a cross-site scr... File : e107_content_preset_xss.nasl - Type : ACT_ATTACK |
2010-05-21 | Name : The remote web server contains a PHP script that allows arbitrary code execut... File : e107_bbcode_php_code_execution.nasl - Type : ACT_ATTACK |
2010-04-21 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_a4746a864c8911df83fb0015587e2cc1.nasl - Type : ACT_GATHER_INFO |
2009-12-10 | Name : A PHP script on the remote web server is affected by a cross-site scripting v... File : e107_submitnews_xss.nasl - Type : ACT_ATTACK |