Vulnerabilities
Vulnerable Software
E107:  >> E107  >> 0.6_10  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment).
CVSS Score
4.3
EPSS Score
0.062
Published
2006-06-27
SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name'].
CVSS Score
5.1
EPSS Score
0.008
Published
2006-05-16
Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.
CVSS Score
4.3
EPSS Score
0.007
Published
2004-05-21


Contact Us

Shodan ® - All rights reserved