SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name'].
2006-05-16T10:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.1 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | e107 | e107 | 0.6_10 | Yes |
Application | e107 | e107 | 0.6_11 | Yes |
Application | e107 | e107 | 0.6_12 | Yes |
Application | e107 | e107 | 0.6_13 | Yes |
Application | e107 | e107 | 0.6_14 | Yes |
Application | e107 | e107 | 0.6_15 | Yes |
Application | e107 | e107 | 0.6_15a | Yes |
Application | e107 | e107 | 0.7 | Yes |
Application | e107 | e107 | 0.7.1 | Yes |
Application | e107 | e107 | 0.7.2 | Yes |
Application | e107 | e107 | 0.545 | Yes |
Application | e107 | e107 | 0.554 | Yes |
Application | e107 | e107 | 0.555_beta | Yes |
Application | e107 | e107 | 0.603 | Yes |
Application | e107 | e107 | 0.616 | Yes |
Application | e107 | e107 | 0.617 | Yes |
Application | e107 | e107 | 0.6171 | Yes |
Application | e107 | e107 | 0.6175 | Yes |