Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

E107 MEDIUM 6.0
CVE-2010-0996

Unrestricted file upload vulnerability in e107 before 0.7.20 allows remote authenticated users to execute arbitrary code by uploading a .php.filetype…

Fix: after 0.7.19
Fix from $1,600 2010-04-20
E107 HIGH 7.5
CVE-2009-4084

SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via unspecifie…

Fix: after 0.7.16
Fix from $1,950 2009-11-29
E107 MEDIUM 5.1
CVE-2009-1409

SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, …

No fix yet
Fix from $1,600 2009-04-24
E107 MEDIUM 6.5
CVE-2008-5320

SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via th…

Fix: after 0.7.13
Fix from $1,600 2008-12-03
Alternate Profiles Plugin HIGH 7.5
CVE-2008-4785

SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL …

No fix yet
Fix from $1,950 2008-10-29
Easyshop Plugin HIGH 7.5
CVE-2008-4786

SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the categor…

No fix yet
Fix from $1,950 2008-10-29
E107 HIGH 7.5
CVE-2008-2020

The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitT…

Mitigation only
Fix from $1,950 2008-04-30
E107 MEDIUM 6.8
CVE-2007-3429

Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload …

No fix yet
Fix from $1,600 2007-06-27
E107 HIGH 7.5
CVE-2006-5786

Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via…

No fix yet
Fix from $1,950 2006-11-07
E107 HIGH 7.5
CVE-2006-4548

e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parame…

No fix yet
Fix from $1,950 2006-09-06
E107 MEDIUM 6.4
CVE-2006-2590

SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

Patch available
Fix from $1,600 2006-05-25
E107 MEDIUM 5.0
CVE-2006-2591

Unspecified vulnerability in e107 before 0.7.5 has unknown impact and remote attack vectors related to an "emailing exploit".

Patch available
Fix from $1,600 2006-05-25
E107 MEDIUM 5.1
CVE-2006-2416

SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined…

Patch available
Fix from $1,600 2006-05-16
E107 HIGH 7.5
CVE-2005-4224

Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hide…

Mitigation only
Fix from $1,950 2005-12-14
E107 MEDIUM 5.0
CVE-2005-4051

e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.

No fix yet
Fix from $1,600 2005-12-07
E107 MEDIUM 5.0
CVE-2005-3594

game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name …

Mitigation only
Fix from $1,600 2005-11-16
E107 HIGH 7.5
CVE-2005-3521

SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentic…

Patch available
Fix from $1,950 2005-11-06
E107 MEDIUM 5.0
CVE-2005-2805

forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.

Mitigation only
Fix from $1,600 2005-09-06
E107 HIGH 7.5
CVE-2005-2559

doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shell metach…

Patch available
Fix from $1,950 2005-08-16
E107 HIGH 7.5
CVE-2005-1949

The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell me…

Mitigation only
Fix from $1,950 2005-06-16
E107 HIGH 7.5
CVE-2005-1966

The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a…

Mitigation only
Fix from $1,950 2005-06-10
E107 HIGH 7.5
CVE-2004-2262EPSS 15%

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by upl…

Fix: 0.617+
Fix from $1,950 2004-12-31
E107 HIGH 7.5
CVE-2004-2042

Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) conte…

Patch available
Fix from $1,950 2004-05-29
E107 MEDIUM 5.0
CVE-2004-2039

e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php…

Patch available
Fix from $1,600 2004-05-29
E107 MEDIUM 5.0
CVE-2003-1191EPSS 8%

chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which preve…

Patch available
Fix from $1,600 2003-10-29