e107 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-5320 - Vulnerability Database

e107 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-5320

Medium
Reference: CVE-2008-5320
Title: e107 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue parameter.