Looking for the vulnerability index of Invicti's legacy products?
e107 Deserialization of Untrusted Data Vulnerability (CVE-2016-10753) - Vulnerability Database

e107 Deserialization of Untrusted Data Vulnerability (CVE-2016-10753)

Description

e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

References

Related Vulnerabilities