|
Family: CGI abuses --> Category: infos
e107 resetcore.php SQL Injection Vulnerability Scan
Vulnerability Scan Summary e107 SQL Injection
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is prone to a SQL
injection attack.
Description :
The remote host appears to be running e107, a web content management
system written in PHP.
There is a flaw in the version of e107 on the remote host such that
anyone can injection SQL commands through the 'resetcore.php' script
which may be used to gain administrative access trivially.
See also :
http://retrogod.altervista.org/e107remote.html
https://sourceforge.net/project/shownotes.php?release_id=364570
Solution :
Upgrade to e107 version 0.6173 or later.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|