// For flags

CVE-2009-4083

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) submitnews.php, (2) usersettings.php; and (3) newpost.php, (4) banlist.php, (5) banner.php, (6) cpage.php, (7) download.php, (8) users_extended.php, (9) frontpage.php, (10) links.php, and (11) mailout.php in e107_admin/. NOTE: this may overlap CVE-2004-2040 and CVE-2006-4794, but there are insufficient details to be certain.

Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados(XSS) en e107 v0.7.16 y anteriores permite a atacantes remotos permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados en (1) submitnews.php, (2) usersettings.php; y (3) newpost.php, (4) banlist.php, (5) banner.php, (6) cpage.php, (7) download.php, (8) users_extended.php, (9) frontpage.php, (10) links.php, y(11) mailout.php en e107_admin/. NOTA: esta vulnerabilidad puede solaparse con CVE-2004-2040 y CVE-2006-4794, pero no hay suficientes detalles para tener certeza.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-11-27 CVE Reserved
  • 2009-11-27 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
<= 0.7.16
Search vendor "E107" for product "E107" and version " <= 0.7.16"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_10
Search vendor "E107" for product "E107" and version "0.6_10"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_11
Search vendor "E107" for product "E107" and version "0.6_11"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_12
Search vendor "E107" for product "E107" and version "0.6_12"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_13
Search vendor "E107" for product "E107" and version "0.6_13"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_14
Search vendor "E107" for product "E107" and version "0.6_14"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_15
Search vendor "E107" for product "E107" and version "0.6_15"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6_15a
Search vendor "E107" for product "E107" and version "0.6_15a"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7
Search vendor "E107" for product "E107" and version "0.7"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.1
Search vendor "E107" for product "E107" and version "0.7.1"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.2
Search vendor "E107" for product "E107" and version "0.7.2"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.3
Search vendor "E107" for product "E107" and version "0.7.3"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.4
Search vendor "E107" for product "E107" and version "0.7.4"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.5
Search vendor "E107" for product "E107" and version "0.7.5"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.6
Search vendor "E107" for product "E107" and version "0.7.6"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.7
Search vendor "E107" for product "E107" and version "0.7.7"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.8
Search vendor "E107" for product "E107" and version "0.7.8"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.9
Search vendor "E107" for product "E107" and version "0.7.9"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.10
Search vendor "E107" for product "E107" and version "0.7.10"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.11
Search vendor "E107" for product "E107" and version "0.7.11"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.12
Search vendor "E107" for product "E107" and version "0.7.12"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.13
Search vendor "E107" for product "E107" and version "0.7.13"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.14
Search vendor "E107" for product "E107" and version "0.7.14"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.7.15
Search vendor "E107" for product "E107" and version "0.7.15"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.545
Search vendor "E107" for product "E107" and version "0.545"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.547_beta
Search vendor "E107" for product "E107" and version "0.547_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.548_beta
Search vendor "E107" for product "E107" and version "0.548_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.549_beta
Search vendor "E107" for product "E107" and version "0.549_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.551_beta
Search vendor "E107" for product "E107" and version "0.551_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.552_beta
Search vendor "E107" for product "E107" and version "0.552_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.553_beta
Search vendor "E107" for product "E107" and version "0.553_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.554
Search vendor "E107" for product "E107" and version "0.554"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.554_beta
Search vendor "E107" for product "E107" and version "0.554_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.555_beta
Search vendor "E107" for product "E107" and version "0.555_beta"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.600
Search vendor "E107" for product "E107" and version "0.600"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.601
Search vendor "E107" for product "E107" and version "0.601"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.602
Search vendor "E107" for product "E107" and version "0.602"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.603
Search vendor "E107" for product "E107" and version "0.603"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.604
Search vendor "E107" for product "E107" and version "0.604"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.605
Search vendor "E107" for product "E107" and version "0.605"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.606
Search vendor "E107" for product "E107" and version "0.606"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.607
Search vendor "E107" for product "E107" and version "0.607"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.608
Search vendor "E107" for product "E107" and version "0.608"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.609
Search vendor "E107" for product "E107" and version "0.609"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.610
Search vendor "E107" for product "E107" and version "0.610"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.611
Search vendor "E107" for product "E107" and version "0.611"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.612
Search vendor "E107" for product "E107" and version "0.612"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.613
Search vendor "E107" for product "E107" and version "0.613"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.614
Search vendor "E107" for product "E107" and version "0.614"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.615
Search vendor "E107" for product "E107" and version "0.615"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.615a
Search vendor "E107" for product "E107" and version "0.615a"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.616
Search vendor "E107" for product "E107" and version "0.616"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.617
Search vendor "E107" for product "E107" and version "0.617"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6171
Search vendor "E107" for product "E107" and version "0.6171"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6172
Search vendor "E107" for product "E107" and version "0.6172"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6173
Search vendor "E107" for product "E107" and version "0.6173"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6174
Search vendor "E107" for product "E107" and version "0.6174"
-
Affected
E107
Search vendor "E107"
E107
Search vendor "E107" for product "E107"
0.6175
Search vendor "E107" for product "E107" and version "0.6175"
-
Affected