This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:e107:e107:0.7.5 |
| Detail | |||
|---|---|---|---|
| Vendor | e107 | First view | 2006-05-25 |
| Product | e107 | Last view | 2012-08-31 |
| Version | 0.7.5 | Type | Application |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/a:e107:e107 | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 6.8 | 2012-08-31 | CVE-2011-4947 | Network | Medium | None Requ... | |
| 6.8 | 2012-08-31 | CVE-2011-4946 | Network | Medium | None Requ... | |
| 6 | 2012-02-14 | CVE-2010-5084 | Network | Medium | Requires ... | |
| 7.5 | 2011-11-04 | CVE-2011-1513 | Network | Low | None Requ... | |
| 4.3 | 2011-03-15 | CVE-2011-0457 | Network | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2011-03-15 | CVE-2010-4757 | Network | Medium | None Requ... | |
| 7.5 | 2010-05-27 | CVE-2010-2099 | Network | Low | None Requ... | |
| 7.5 | 2010-05-27 | CVE-2010-2098 | Network | Low | None Requ... | |
| 3.5 | 2010-04-20 | CVE-2010-0997 | Network | Medium | Requires ... | |
| 6 | 2010-04-20 | CVE-2010-0996 | Network | Medium | Requires ... | |
| 7.5 | 2009-11-29 | CVE-2009-4084 | Network | Low | None Requ... | |
| 4.3 | 2009-11-29 | CVE-2009-4083 | Network | Medium | None Requ... | |
| 4.3 | 2009-09-28 | CVE-2009-3444 | Network | Medium | None Requ... | |
| 5.1 | 2009-04-24 | CVE-2009-1409 | Network | High | None Requ... | |
| 6.5 | 2008-12-03 | CVE-2008-5320 | Network | Low | Requires ... | |
| 6.8 | 2007-06-26 | CVE-2007-3429 | Network | Medium | None Requ... | |
| 7.5 | 2006-11-07 | CVE-2006-5786 | Network | Low | None Requ... | |
| 4.3 | 2006-09-14 | CVE-2006-4794 | Network | Medium | None Requ... | |
| 4.6 | 2006-09-13 | CVE-2006-4757 | Network | High | Requires ... | |
| 7.5 | 2006-09-05 | CVE-2006-4548 | Network | Low | None Requ... | |
| 4.3 | 2006-06-27 | CVE-2006-3259 | Network | Medium | None Requ... | |
| 5 | 2006-05-25 | CVE-2006-2591 | Network | Low | None Requ... | |
| 6.4 | 2006-05-25 | CVE-2006-2590 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 38% (5) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 30% (4) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
| 15% (2) | CWE-352 | Cross-Site Request Forgery (CSRF) |
| 7% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
| 7% (1) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |
Open Source Vulnerability Database (OSVDB)
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| id | Description |
|---|---|
| 77042 | e107 CMS install_.php MySQL Server Name Parsing Remote PHP Code Execution |
| 67367 | e107 submitnews.php submitnews_title Parameter XSS |
| 65243 | e107 bbcode/php.bb Access Control Check Weakness Arbitrary PHP Code Execution |
| 65056 | e107 usersettings.php loginname Parameter Blacklist Weakness SQL Injection |
| 63911 | e107 e107_plugins/content/content_manager.php content_heading Parameter XSS |
| id | Description |
|---|---|
| 63910 | e107 Crafted .php.filetypesphp Image File Upload Arbitrary PHP Code Execution |
| 60829 | e107 e107_admin/mailout.php Unspecified Parameter XSS |
| 60828 | e107 e107_admin/links.php Unspecified Parameter XSS |
| 60827 | e107 e107_admin/frontpage.php Unspecified Parameter XSS |
| 60826 | e107 e107_admin/users_extended.php Unspecified Parameter XSS |
| 60825 | e107 e107_admin/download.php Unspecified Parameter XSS |
| 60824 | e107 e107_admin/cpage.php Unspecified Parameter XSS |
| 60823 | e107 e107_admin/banner.php Unspecified Parameter XSS |
| 60822 | e107 e107_admin/banlist.php Unspecified Parameter XSS |
| 60821 | e107 e107_admin/newpost.php Unspecified Parameter XSS |
| 60820 | e107 e107_admin/usersettings.php Unspecified Parameter XSS |
| 60819 | e107 e107_admin/submitnews.php Unspecified Parameter XSS |
| 60608 | e107 Search Feature Unspecified SQL Injection |
| 58363 | e107 email.php HTTP Referer Header XSS |
| 53812 | e107 usersettings.php hide Parameter SQL Injection |
| 49207 | e107 usersettings.php ue[] Array Parameter SQL Injection |
| 45426 | e107 signup.php Double Extension Unrestricted File Upload Arbitrary Code Exec... |
| 33920 | e107 class2.php e107language_e107cookie Cookie Traversal Local File Inclusion |
| 30987 | e107 download.php Query String (PATH_INFO) Parameter XSS |
| 30986 | e107 user.php Query String (PATH_INFO) Parameter XSS |
Milw0rm Exploits
| id | Description |
|---|---|
| 2009-04-20 | e107 <= 0.7.15 (extended_user_fields) Blind SQL Injection Exploit |
| 2008-10-19 | e107 <= 0.7.13 (usersettings.php) Blind SQL Injection Exploit |
| 2007-06-24 | e107 <= 0.7.8 (photograph) Arbitrary File Upload Vulnerability |
| 2006-11-04 | e107 <= 0.75 (e107language_e107cookie) Local File Include Exploit |








