e107 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-5320 - Vulnerability Database
e107 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-5320
Medium
Reference:
CVE-2008-5320
Title:
e107 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue parameter.