Vulnerabilities > E107 > E107 > 0.6.13
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-06-27 | CVE-2006-3259 | Cross-Site Scripting vulnerability in e107 Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment). network e107 | 4.3 |
2006-05-16 | CVE-2006-2416 | SQL Injection vulnerability in E107 SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name']. | 5.1 |
2004-05-21 | CVE-2004-2028 | HTML Injection vulnerability in e107 Website System Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php. network e107 | 4.3 |