CVE-2006-4794: XSS
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (PATHINFO) in (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php, (7) signup.php, (8) submitnews.php, and (9) user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4794?
CVE-2006-4794 has been classified as a moderate severity vulnerability due to its potential impact on web application security.
How do I fix CVE-2006-4794?
To fix CVE-2006-4794, update e107 CMS to a version later than 0.7.5 that addresses these cross-site scripting vulnerabilities.
What software is affected by CVE-2006-4794?
CVE-2006-4794 affects e107 CMS version 0.7.5.
What type of attack is CVE-2006-4794 associated with?
CVE-2006-4794 is associated with cross-site scripting (XSS) attacks that allow attackers to inject arbitrary scripts.
What components of e107 are vulnerable in CVE-2006-4794?
The vulnerable components in e107 0.7.5 include contact.php, download.php, admin.php, fpw.php, news.php, search.php, signup.php, and submitnews.php.