vendor:
e107 Website System
by:
SecurityFocus
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: e107 Website System
Affected Version From: 0.7.0
Affected Version To: 2000.7.11
Patch Exists: YES
Related CWE: N/A
CPE: a:e107:e107
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
e107 Website System SQL Injection Vulnerability
e107 Website System is prone to an SQL injection vulnerability. This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Mitigation:
Input validation should be used to prevent malicious input from being passed to database queries.