vendor:
e107
by:
Steve Dunstan
7.5
CVSS
HIGH
Arbitrary Variable Overwriting
94
CWE
Product Name: e107
Affected Version From: e107 <= 0.7.11
Affected Version To: e107 <= 0.7.11
Patch Exists: YES
Related CWE: N/A
CPE: e107
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2008
e107 <= 0.7.11 Arbitrary Variable Overwriting
e107 is a popular full featured content management system written in php. Unfortunately e107 suffers from an arbitrary variable overwriting issue within it's download.php file that allows a number of possible attacks to happen including, but possibly not limited to, arbitrary php code execution and SQL Injection. No authentication is required to exploit the issue and it can be exploited regardless of php magic quotes settings.
Mitigation:
Upgrade e107 installations as soon as possible.