PT-2005-4787 · E107 · E107

Marc Ruef

+1

·

Published

2005-12-07

·

Updated

2018-10-19

·

CVE-2005-4052

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions e107 version 0.6174
Description The issue allows remote attackers to redirect users to other web sites via the download parameter in "rate.php". This occurs after a user submits a file download rating. By default, the e BASE variable restricts the redirection to the same web site.
Recommendations For e107 version 0.6174, consider restricting access to the "rate.php" file or validating the download parameter to prevent unauthorized redirects. As a temporary workaround, restrict the e BASE variable to limit redirections to the same web site.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4052

Affected Products

E107