Vulnerabilities > E107 > E107 > 5.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-04-24 | CVE-2009-1409 | SQL Injection vulnerability in E107 SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320. | 5.1 |
2006-02-15 | CVE-2006-0682 | HTML Injection vulnerability in E107 Website System BBCode Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. network e107 | 4.3 |