- EPSS 1.78%
- Veröffentlicht 29.05.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:08:52
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP erro...
CVE-2004-2031
- EPSS 1.26%
- Veröffentlicht 21.05.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:08:51
Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.
CVE-2004-2028
- EPSS 3.51%
- Veröffentlicht 21.05.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:08:51
Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.
- EPSS 7.87%
- Veröffentlicht 29.10.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:03:41
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.