Showing posts with label e107. Show all posts
Showing posts with label e107. Show all posts

Wednesday, 27 May 2015

SQLI in e107 CMS

During last few weeks in the middle of time I was doing also some source code review.
That's how I found sqli bug in admin panel in e107 CMS. After a fast response from e107 Team,
fix was created.

This bug was found in e107_2.0_full_beta1 version. I don't know if other versions are also vulnerable.

Details about the vulnerability (even when it's in admin panel) will not be published for now.

Stay in touch. ;)


Wednesday, 9 January 2013

[EN] e107 CMS 1.0.2 SQL Injection

Yes it's true, but calm down. This vulnerability can be triggered only by admin. ;)

If attacker is able to get admin's password, then vulnerability status can 'increase' from
low to high.

Anyway, more details soon.

If you need it faster - mail me.

Monday, 27 August 2012

[EN] Reflected XSS in latest e107 CMS (1.0.1)

Hi ;)

Some one asked me about this case in mail, so here is the answer:


1. Go to 'register' page:


2. As Your e-mail confirmation, add yourm@il +  code from screen nr 3:




3. View from Burp Proxy:



4. ... and another one, parameters:



Cheers ;)

o/