The provided text describes an SQL injection vulnerability in e107 0.7.25, where user-supplied data is insufficiently sanitized in the 'news.php' file. The example URL demonstrates a basic SQLi payload to extract database version information.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:e107 0.7.25
No auth needed
Prerequisites:Access to the vulnerable 'news.php' endpoint