e107 CMS 'download.php' Arbitrary Variable Overwrite Vulnerability

e107 CMS is prone to a vulnerability that lets attackers overwrite arbitrary variables.

Attackers can leverage this issue to launch SQL-injection attacks or to execute arbitrary PHP code. This may result in the compromise of the affected application.

e107 CMS 0.7.11 is vulnerable; other versions may also be affected.

NOTE: This BID was previously titled 'e107 CMS 'download.php' SQL Injection Vulnerability'. It has been updated to better reflect the nature of the vulnerability.


Privacy Statement
Copyright 2010, SecurityFocus