CVE-2006-4757
Title: E107 Injection (SQLi/OSi)
Proof Of Concept
No public PoC currently indexed for CVE-2006-4757.
Vulnerability Summary
CVE-2006-4757: Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."
Impacted Vendors
Reference Links
AV:N/AC:H/Au:S/C:P/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
CVE-2006-4757 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
Vulnerability data updated via NVD.
Vulnerability data or affected products updated.
Vulnerability first announced in NVD.
Attack Vector Matrix
AV:N/AC:H/Au:S/C:P/I:P/A:P
Affected Stack
No specific products linked.