[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-4757Date: (C)2006-09-13   (M)2023-12-22


Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication:
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SREASON-1569
http://www.securityfocus.com/archive/1/archive/1/445005/100/100/threaded
http://e107.org/e107_plugins/bugtrack/bugtrack.php?id=3195&action=show

CPE    6
cpe:/a:e107:e107:0.7.5
cpe:/a:e107:e107:0.7.3
cpe:/a:e107:e107:0.7.4
cpe:/a:e107:e107:0.7.1
...

© SecPod Technologies