Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hideemail, image, realname, signature, timezone, and xupexist parameters in signup.php, (2) the content_comment, content_rating, and content_summary parameters in subcontent.php, (3) the download_category and file_demo in upload.php, and (4) the email, hideemail, user_timezone, and user_xup parameters in usersettings.php.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2005-12-14T11:00:00
Updated: 2024-08-07T23:38:51.474Z
Reserved: 2005-12-14T00:00:00
Link: CVE-2005-4224
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2005-12-14T11:03:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-4224
 Redhat
                        Redhat
                    No data.