CVE-2008-5320: SQL Injection
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5320?
CVE-2008-5320 has a medium severity level, considering its potential to allow unauthorized SQL commands to be executed.
How do I fix CVE-2008-5320?
To fix CVE-2008-5320, upgrade to a version of e107 CMS that is 0.7.14 or later, which addresses the SQL injection vulnerability.
Who is affected by CVE-2008-5320?
Authenticated users of e107 CMS versions 0.7.13 and earlier are affected by CVE-2008-5320 due to SQL injection capabilities.
What tool can help identify CVE-2008-5320 in my system?
Using web application security scanning tools can help identify vulnerabilities like CVE-2008-5320 in your e107 CMS installation.
What kind of attacks can be executed via CVE-2008-5320?
An attacker exploiting CVE-2008-5320 can perform unauthorized SQL operations, which could compromise the database and application integrity.