// For flags

CVE-2009-3444

e107 0.7.16 - Referer header Cross-Site Scripting

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action.

Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en email.php en e107 v0.7.16 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de la cabecera HTTP Referer en una acción news.1 (también conocida como noticias (news) a correo (email).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-09-24 First Exploit
  • 2009-09-28 CVE Reserved
  • 2009-09-28 CVE Published
  • 2024-01-01 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
<= 0.7.16
Search vendor "E107" for product "E107" and version " <= 0.7.16"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_10
Search vendor "E107" for product "E107" and version "0.6_10"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_11
Search vendor "E107" for product "E107" and version "0.6_11"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_12
Search vendor "E107" for product "E107" and version "0.6_12"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_13
Search vendor "E107" for product "E107" and version "0.6_13"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_14
Search vendor "E107" for product "E107" and version "0.6_14"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_15
Search vendor "E107" for product "E107" and version "0.6_15"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_15a
Search vendor "E107" for product "E107" and version "0.6_15a"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7
Search vendor "E107" for product "E107" and version "0.7"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.1
Search vendor "E107" for product "E107" and version "0.7.1"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.2
Search vendor "E107" for product "E107" and version "0.7.2"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.3
Search vendor "E107" for product "E107" and version "0.7.3"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.4
Search vendor "E107" for product "E107" and version "0.7.4"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.5
Search vendor "E107" for product "E107" and version "0.7.5"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.6
Search vendor "E107" for product "E107" and version "0.7.6"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.7
Search vendor "E107" for product "E107" and version "0.7.7"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.8
Search vendor "E107" for product "E107" and version "0.7.8"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.9
Search vendor "E107" for product "E107" and version "0.7.9"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.10
Search vendor "E107" for product "E107" and version "0.7.10"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.11
Search vendor "E107" for product "E107" and version "0.7.11"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.12
Search vendor "E107" for product "E107" and version "0.7.12"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.13
Search vendor "E107" for product "E107" and version "0.7.13"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.14
Search vendor "E107" for product "E107" and version "0.7.14"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.15
Search vendor "E107" for product "E107" and version "0.7.15"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.545
Search vendor "E107" for product "E107" and version "0.545"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.547_beta
Search vendor "E107" for product "E107" and version "0.547_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.548_beta
Search vendor "E107" for product "E107" and version "0.548_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.549_beta
Search vendor "E107" for product "E107" and version "0.549_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.551_beta
Search vendor "E107" for product "E107" and version "0.551_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.552_beta
Search vendor "E107" for product "E107" and version "0.552_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.553_beta
Search vendor "E107" for product "E107" and version "0.553_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.554
Search vendor "E107" for product "E107" and version "0.554"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.554_beta
Search vendor "E107" for product "E107" and version "0.554_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.555_beta
Search vendor "E107" for product "E107" and version "0.555_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.600
Search vendor "E107" for product "E107" and version "0.600"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.601
Search vendor "E107" for product "E107" and version "0.601"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.602
Search vendor "E107" for product "E107" and version "0.602"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.603
Search vendor "E107" for product "E107" and version "0.603"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.604
Search vendor "E107" for product "E107" and version "0.604"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.605
Search vendor "E107" for product "E107" and version "0.605"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.606
Search vendor "E107" for product "E107" and version "0.606"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.607
Search vendor "E107" for product "E107" and version "0.607"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.608
Search vendor "E107" for product "E107" and version "0.608"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.609
Search vendor "E107" for product "E107" and version "0.609"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.610
Search vendor "E107" for product "E107" and version "0.610"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.611
Search vendor "E107" for product "E107" and version "0.611"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.612
Search vendor "E107" for product "E107" and version "0.612"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.613
Search vendor "E107" for product "E107" and version "0.613"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.614
Search vendor "E107" for product "E107" and version "0.614"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.615
Search vendor "E107" for product "E107" and version "0.615"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.615a
Search vendor "E107" for product "E107" and version "0.615a"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.616
Search vendor "E107" for product "E107" and version "0.616"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.617
Search vendor "E107" for product "E107" and version "0.617"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6171
Search vendor "E107" for product "E107" and version "0.6171"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6172
Search vendor "E107" for product "E107" and version "0.6172"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6173
Search vendor "E107" for product "E107" and version "0.6173"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6174
Search vendor "E107" for product "E107" and version "0.6174"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6175
Search vendor "E107" for product "E107" and version "0.6175"
-
Affected