First published: Tue Apr 20 2010(Updated: )
Unrestricted file upload vulnerability in e107 before 0.7.20 allows remote authenticated users to execute arbitrary code by uploading a .php.filetypesphp file. NOTE: the vendor disputes the significance of this issue, noting that "an odd set of preferences and a missing file" are required.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.6175 | |
e107 CMS | =5.3-beta | |
e107 CMS | =0.616 | |
e107 CMS | =0.7.10 | |
e107 CMS | =0.6174 | |
e107 CMS | =5.05 | |
e107 CMS | =0.615a | |
e107 CMS | =0.7.7 | |
e107 CMS | =5.21 | |
e107 CMS | =0.7.13 | |
e107 CMS | =5.4-beta5 | |
e107 CMS | =0.7.4 | |
e107 CMS | =5.3-beta2 | |
e107 CMS | =0.6173 | |
e107 CMS | =0.610 | |
e107 CMS | =0.7.14 | |
e107 CMS | =0.7.5 | |
e107 CMS | =0.607 | |
e107 CMS | =0.7.2 | |
e107 CMS | =0.609 | |
e107 CMS | =0.7.11 | |
e107 CMS | =0.554 | |
e107 CMS | =0.552-beta | |
e107 CMS | =0.545 | |
e107 CMS | =5.4-beta1 | |
e107 CMS | =0.606 | |
e107 CMS | =0.602 | |
e107 CMS | =0.547-beta | |
e107 CMS | =0.7 | |
e107 CMS | =0.7.1 | |
e107 CMS | =0.548-beta | |
e107 CMS | =5.4-beta2 | |
e107 CMS | =5.4-beta4 | |
e107 CMS | =0.553-beta | |
e107 CMS | =0.600 | |
e107 CMS | =5.4-beta6 | |
e107 CMS | <=0.7.19 | |
e107 CMS | =0.615 | |
e107 CMS | =0.613 | |
e107 CMS | =0.604 | |
e107 CMS | =0.603 | |
e107 CMS | =0.7.16 | |
e107 CMS | =5.4-beta3 | |
e107 CMS | =0.614 | |
e107 CMS | =0.554-beta | |
e107 CMS | =0.7.15 | |
e107 CMS | =0.6172 | |
e107 CMS | =0.7.12 | |
e107 CMS | =0.7.17 | |
e107 CMS | =0.555-beta | |
e107 CMS | =0.601 | |
e107 CMS | =0.7.8 | |
e107 CMS | =0.608 | |
e107 CMS | =0.7.9 | |
e107 CMS | =0.7.18 | |
e107 CMS | =0.611 | |
e107 CMS | =0.605 | |
e107 CMS | =0.7.6 | |
e107 CMS | =0.617 | |
e107 CMS | =0.612 | |
e107 CMS | =5.1 | |
e107 CMS | =5.04 | |
e107 CMS | =0.6171 | |
e107 CMS | =0.549-beta | |
e107 CMS | =0.551-beta | |
e107 CMS | =0.7.3 | |
<=0.7.19 | ||
=0.7 | ||
=0.7.1 | ||
=0.7.2 | ||
=0.7.3 | ||
=0.7.4 | ||
=0.7.5 | ||
=0.7.6 | ||
=0.7.7 | ||
=0.7.8 | ||
=0.7.9 | ||
=0.7.10 | ||
=0.7.11 | ||
=0.7.12 | ||
=0.7.13 | ||
=0.7.14 | ||
=0.7.15 | ||
=0.7.16 | ||
=0.7.17 | ||
=0.7.18 | ||
=0.545 | ||
=0.547-beta | ||
=0.548-beta | ||
=0.549-beta | ||
=0.551-beta | ||
=0.552-beta | ||
=0.553-beta | ||
=0.554 | ||
=0.554-beta | ||
=0.555-beta | ||
=0.600 | ||
=0.601 | ||
=0.602 | ||
=0.603 | ||
=0.604 | ||
=0.605 | ||
=0.606 | ||
=0.607 | ||
=0.608 | ||
=0.609 | ||
=0.610 | ||
=0.611 | ||
=0.612 | ||
=0.613 | ||
=0.614 | ||
=0.615 | ||
=0.615a | ||
=0.616 | ||
=0.617 | ||
=0.6171 | ||
=0.6172 | ||
=0.6173 | ||
=0.6174 | ||
=0.6175 | ||
=5.1 | ||
=5.3-beta | ||
=5.3-beta2 | ||
=5.04 | ||
=5.4-beta1 | ||
=5.4-beta2 | ||
=5.4-beta3 | ||
=5.4-beta4 | ||
=5.4-beta5 | ||
=5.4-beta6 | ||
=5.05 | ||
=5.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0996 is considered a medium severity vulnerability due to the unauthorized ability to execute arbitrary code.
To fix CVE-2010-0996, upgrade to e107 version 0.7.20 or later, which addresses the unrestricted file upload issue.
CVE-2010-0996 is an unrestricted file upload vulnerability that allows for potentially malicious code execution.
CVE-2010-0996 affects e107 CMS versions prior to 0.7.20, including various earlier releases.
An attacker exploiting CVE-2010-0996 can upload a malicious .php file, potentially leading to remote code execution.