During last few weeks in the middle of time I was doing also some source code review.
That's how I found sqli bug in admin panel in e107 CMS. After a fast response from e107 Team,
fix was created.
This bug was found in e107_2.0_full_beta1 version. I don't know if other versions are also vulnerable.
Details about the vulnerability (even when it's in admin panel) will not be published for now.
Stay in touch. ;)
Showing posts with label e107. Show all posts
Showing posts with label e107. Show all posts
Wednesday, 27 May 2015
Wednesday, 9 January 2013
[EN] e107 CMS 1.0.2 SQL Injection
Yes it's true, but calm down. This vulnerability can be triggered only by admin. ;)
If attacker is able to get admin's password, then vulnerability status can 'increase' from
low to high.
Anyway, more details soon.
If you need it faster - mail me.
If attacker is able to get admin's password, then vulnerability status can 'increase' from
low to high.
Anyway, more details soon.
If you need it faster - mail me.
Monday, 27 August 2012
[EN] Reflected XSS in latest e107 CMS (1.0.1)
Hi ;)
Some one asked me about this case in mail, so here is the answer:
1. Go to 'register' page:
2. As Your e-mail confirmation, add yourm@il + code from screen nr 3:
3. View from Burp Proxy:
4. ... and another one, parameters:
Cheers ;)
o/
Some one asked me about this case in mail, so here is the answer:
1. Go to 'register' page:
3. View from Burp Proxy:
4. ... and another one, parameters:
Cheers ;)
o/
Subscribe to:
Posts (Atom)



