Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.67358
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: e107
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: e107

CVE-2010-0996
Unrestricted file upload vulnerability in e107 before 0.7.20 allows
remote authenticated users to execute arbitrary code by uploading a
.php.filetypesphp file. NOTE: the vendor disputes the significance of
this issue, noting that 'an odd set of preferences and a missing file'
are required.

CVE-2010-0997
Cross-site scripting (XSS) vulnerability in
107_plugins/content/content_manager.php in the Content Management
plugin in e107 before 0.7.20, when the personal content manager is
enabled, allows user-assisted remote authenticated users to inject
arbitrary web script or HTML via the content_heading parameter.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
6.0

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-0996
BugTraq ID: 39540
http://www.securityfocus.com/bid/39540
Bugtraq: 20100419 Secunia Research: e107 Avatar/Photograph Image File Upload Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/510805/100/0/threaded
http://e107.org/svn_changelog.php?version=0.7.20
http://secunia.com/secunia_research/2010-44/
http://secunia.com/advisories/39013
http://www.vupen.com/english/advisories/2010/0919
XForce ISS Database: e107-phpfiletypesphp-file-upload(57932)
https://exchange.xforce.ibmcloud.com/vulnerabilities/57932
Common Vulnerability Exposure (CVE) ID: CVE-2010-0997
BugTraq ID: 39539
http://www.securityfocus.com/bid/39539
Bugtraq: 20100419 Secunia Research: e107 Content Management Plugin Script Insertion Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/510809/100/0/threaded
http://secunia.com/secunia_research/2010-43/
XForce ISS Database: e107-contentmanager-xss(57933)
https://exchange.xforce.ibmcloud.com/vulnerabilities/57933
CopyrightCopyright (C) 2010 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.