📦

e107

Vendor: e107

Actively Exploited 0 CISA KEV List
PoC / Exploits 29 Code Available
Total RCEs 11 Remote Access
Total CVEs 1122 Total Indexed
Avg. EPSS 1.93% Exploit Prob.
Latest CVE CVE-2022-50939 Jan 13

Security Vulnerability Index

Page 6 / 113
7.5 CVSS
CVE-2008-6114
Exploit Found

SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitrary SQL commands via the product parameter.

EPSS: 1.10%
6.8 CVSS

SQL injection vulnerability in e107chat.php in the eChat plugin 4.2 for e107, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.

EPSS: 0.99%
6.5 CVSS
CVE-2008-5320
Exploit Found

SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.

EPSS: 1.94%
7.5 CVSS
CVE-2008-4906
Exploit Found

SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.

EPSS: 1.15%
7.5 CVSS
CVE-2008-4786
Exploit Found

SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

EPSS: 1.01%
7.5 CVSS
CVE-2008-4785
Exploit Found

SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: 1.01%
7.5 CVSS

The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg background image and the PHP ImageString function in a way that produces an insufficient number of different images, which allows remote attackers to pass the CAPTCHA test via an automated attack using a table of all possible image checksums and their corresponding digit strings.

EPSS: 1.67%
10.0 CVSS
CVE-2008-1989
RCE Exploit Found

PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.

EPSS: 3.57%
4.3 CVSS
CVE-2008-1702
Exploit Found

Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a full pathname in the file parameter. NOTE: some of these details are obtained from third party information.

EPSS: 5.72%
6.8 CVSS
CVE-2007-3429
Exploit Found

Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.

EPSS: 2.07%