e107 0.7.5 - 'Subject' HTML Injection
Author: EllipSiS Security
type: webapps
platform: php
port:
date_added: 2006-06-21
date_updated: 2013-09-04
verified: 1
codes: CVE-2006-3259;OSVDB-26685
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/18560/info
The e107 CMS is prone to an HTML-injection vulnerability.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site when the inserted data is viewed.
In Submit comment:
Subject: '><script>alert(/XSS/)</script>