CVE Vulnerabilities

CVE-2005-3521

Published: Nov 06, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.

Affected Software

NameVendorStart VersionEnd Version
E107E1070.617 (including)0.617 (including)
E107E1070.6171 (including)0.6171 (including)
E107E1070.6172 (including)0.6172 (including)

References