CVE-2009-1409

SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:e107:e107:0.7.11:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.13:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.553_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.549_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.551_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_12:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_11:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.603:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.602:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.609:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.610:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.616:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.10:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.05:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.555_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.554:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_10:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.545:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.600:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.4_beta3:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.4_beta1:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_15a:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.547_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.601:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.3_beta2:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.548_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.9:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.611:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.4_beta4:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.617:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.04:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6175:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6174:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.615a:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.7:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_15:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.21:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.4:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6173:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.5:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.607:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:*:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.4_beta6:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.606:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.554_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_13:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.552_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.615:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.613:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.604:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.614:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6172:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.2:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.8:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_14:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.608:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.605:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.3_beta:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.4_beta5:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.6:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.612:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:5.1:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6171:*:*:*:*:*:*:*

Information

Published : 2009-04-24 07:30

Updated : 2017-09-28 18:34


NVD link : CVE-2009-1409

Mitre link : CVE-2009-1409


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

e107

  • e107