First published: Wed Dec 07 2005(Updated: )
e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating. NOTE: in the default installation, the e_BASE variable restricts the redirection to the same web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.6174 | |
e107 CMS | =0.6174 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4052 is classified as a potential security vulnerability that allows redirection of users to external sites.
To fix CVE-2005-4052, update to a newer version of e107 or implement validation checks on the download parameter.
CVE-2005-4052 affects users of e107 CMS version 0.6174.
The impact of CVE-2005-4052 is the potential for unauthorized redirection of users, which could lead to phishing attacks.
CVE-2005-4052 can be exploited remotely, making it a relatively easy target for attackers.