123 flash chat commands3/10/2023 In e107 v2.1.7, output without filtering results in XSS.Į107 2.1.7 has CSRF resulting in arbitrary user deletion.Į107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. php filename with the image/jpeg content type.Į107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.Į107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators. There is a XSS attack on e107_admin/comment.php.Į107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.Į107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.Į107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a. Usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.Īn issue was discovered in e107 v2.1.9.
0 Comments
Leave a Reply.AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |