CVE-2015-1041: XSS
Cross-site scripting (XSS) vulnerability in e107admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107files/ file path in the QUERYSTRING.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1041?
CVE-2015-1041 is rated as a medium severity vulnerability due to its potential for unauthorized script execution.
How do I fix CVE-2015-1041?
To fix CVE-2015-1041, upgrade to a patched version of e107 that addresses the cross-site scripting vulnerability.
What are the consequences of exploiting CVE-2015-1041?
Exploitation of CVE-2015-1041 can lead to unauthorized data manipulation and compromise of user sessions.
Who is affected by CVE-2015-1041?
CVE-2015-1041 affects users of e107 version 1.0.4 and potentially earlier versions that utilize the vulnerable file manager.
How can I detect if CVE-2015-1041 is being exploited?
You can detect exploitation of CVE-2015-1041 by monitoring for unusual requests targeting the e107_admin/filemanager.php script with suspicious input.