CVE-2011-1513

e107 CMS <0.7.24 - Code Injection

Title source: llm
STIX 2.1

Description

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matt Bergin · textwebappsphp
https://www.exploit-db.com/exploits/36252

References (4)

Core 4

Scores

EPSS 0.0139
EPSS Percentile 80.5%

Details

CWE
CWE-78
Status published
Products (49)
e107/e107 0.7
e107/e107 0.7.0
e107/e107 0.7.1
e107/e107 0.7.2
e107/e107 0.7.3
e107/e107 0.7.4
e107/e107 0.7.5
e107/e107 0.7.6
e107/e107 0.7.7
e107/e107 0.7.8
... and 39 more
Published Nov 04, 2011
Tracked Since Feb 18, 2026