// For flags

CVE-2009-1409

e107 < 0.7.15 - 'extended_user_fields' Blind SQL Injection

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.

Una vulnerabilidad de inyección de SQL en usersettings.php en e107 v0.7.15 y anteriores, cuando la opción "Campos de usuario extendidos" está activado y magic_quotes_gpc está desactivado, permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro Hide. Se trata de un vector diferente al de CVE-2005-4224 y CVE-2008-5320.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-04-24 CVE Reserved
  • 2009-04-24 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
<= 0.7.15
Search vendor "E107" for product "E107" and version " <= 0.7.15"
-
Safe
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_10
Search vendor "E107" for product "E107" and version "0.6_10"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_11
Search vendor "E107" for product "E107" and version "0.6_11"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_12
Search vendor "E107" for product "E107" and version "0.6_12"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_13
Search vendor "E107" for product "E107" and version "0.6_13"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_14
Search vendor "E107" for product "E107" and version "0.6_14"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_15
Search vendor "E107" for product "E107" and version "0.6_15"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_15a
Search vendor "E107" for product "E107" and version "0.6_15a"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7
Search vendor "E107" for product "E107" and version "0.7"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.1
Search vendor "E107" for product "E107" and version "0.7.1"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.2
Search vendor "E107" for product "E107" and version "0.7.2"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.3
Search vendor "E107" for product "E107" and version "0.7.3"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.4
Search vendor "E107" for product "E107" and version "0.7.4"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.5
Search vendor "E107" for product "E107" and version "0.7.5"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.6
Search vendor "E107" for product "E107" and version "0.7.6"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.7
Search vendor "E107" for product "E107" and version "0.7.7"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.8
Search vendor "E107" for product "E107" and version "0.7.8"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.9
Search vendor "E107" for product "E107" and version "0.7.9"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.10
Search vendor "E107" for product "E107" and version "0.7.10"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.11
Search vendor "E107" for product "E107" and version "0.7.11"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.13
Search vendor "E107" for product "E107" and version "0.7.13"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.545
Search vendor "E107" for product "E107" and version "0.545"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.547_beta
Search vendor "E107" for product "E107" and version "0.547_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.548_beta
Search vendor "E107" for product "E107" and version "0.548_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.549_beta
Search vendor "E107" for product "E107" and version "0.549_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.551_beta
Search vendor "E107" for product "E107" and version "0.551_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.552_beta
Search vendor "E107" for product "E107" and version "0.552_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.553_beta
Search vendor "E107" for product "E107" and version "0.553_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.554
Search vendor "E107" for product "E107" and version "0.554"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.554_beta
Search vendor "E107" for product "E107" and version "0.554_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.555_beta
Search vendor "E107" for product "E107" and version "0.555_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.600
Search vendor "E107" for product "E107" and version "0.600"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.601
Search vendor "E107" for product "E107" and version "0.601"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.602
Search vendor "E107" for product "E107" and version "0.602"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.603
Search vendor "E107" for product "E107" and version "0.603"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.604
Search vendor "E107" for product "E107" and version "0.604"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.605
Search vendor "E107" for product "E107" and version "0.605"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.606
Search vendor "E107" for product "E107" and version "0.606"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.607
Search vendor "E107" for product "E107" and version "0.607"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.608
Search vendor "E107" for product "E107" and version "0.608"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.609
Search vendor "E107" for product "E107" and version "0.609"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.610
Search vendor "E107" for product "E107" and version "0.610"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.611
Search vendor "E107" for product "E107" and version "0.611"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.612
Search vendor "E107" for product "E107" and version "0.612"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.613
Search vendor "E107" for product "E107" and version "0.613"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.614
Search vendor "E107" for product "E107" and version "0.614"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.615
Search vendor "E107" for product "E107" and version "0.615"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.615a
Search vendor "E107" for product "E107" and version "0.615a"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.616
Search vendor "E107" for product "E107" and version "0.616"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.617
Search vendor "E107" for product "E107" and version "0.617"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6171
Search vendor "E107" for product "E107" and version "0.6171"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6172
Search vendor "E107" for product "E107" and version "0.6172"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6173
Search vendor "E107" for product "E107" and version "0.6173"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6174
Search vendor "E107" for product "E107" and version "0.6174"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6175
Search vendor "E107" for product "E107" and version "0.6175"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
1.0.1
Search vendor "E107" for product "E107" and version "1.0.1"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.1
Search vendor "E107" for product "E107" and version "5.1"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.2
Search vendor "E107" for product "E107" and version "5.2"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.3_beta
Search vendor "E107" for product "E107" and version "5.3_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.3_beta2
Search vendor "E107" for product "E107" and version "5.3_beta2"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.04
Search vendor "E107" for product "E107" and version "5.04"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.4_beta1
Search vendor "E107" for product "E107" and version "5.4_beta1"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.4_beta3
Search vendor "E107" for product "E107" and version "5.4_beta3"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.4_beta4
Search vendor "E107" for product "E107" and version "5.4_beta4"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.4_beta5
Search vendor "E107" for product "E107" and version "5.4_beta5"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.4_beta6
Search vendor "E107" for product "E107" and version "5.4_beta6"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.05
Search vendor "E107" for product "E107" and version "5.05"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
5.21
Search vendor "E107" for product "E107" and version "5.21"
-
Affected