CVE Vulnerabilities

CVE-2005-3521

Published: Nov 06, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.

Affected Software

Name Vendor Start Version End Version
E107 E107 0.617 (including) 0.617 (including)
E107 E107 0.6171 (including) 0.6171 (including)
E107 E107 0.6172 (including) 0.6172 (including)

References