CVE-2016-10378: SQL Injection
Published May 29, 2017
·Updated
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107admin/menus.php, related to the menuSaveVisibility function.
Affected Software
1 affected component
e107 e107=2.1.1
Event History
May 29, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10378?
CVE-2016-10378 has a high severity due to its potential to allow SQL injection attacks.
2
How do I fix CVE-2016-10378?
To fix CVE-2016-10378, update e107 to a version beyond 2.1.1 where the vulnerability has been addressed.
3
Who is affected by CVE-2016-10378?
CVE-2016-10378 affects remote authenticated administrators using e107 version 2.1.1.
4
What are the implications of CVE-2016-10378?
The implications of CVE-2016-10378 include unauthorized database access and manipulation capabilities.
5
How can I detect CVE-2016-10378 in my application?
You can detect CVE-2016-10378 by checking for vulnerable versions and testing the pagelist parameter for SQL injection vulnerabilities.