e107 suffers from a cross site scripting vulnerability in the registration page.
711a1942ca5606e2c2803b63fcc66ee6109cee7ab973f852fe41a6812590e6ed
[ TITLE ....... ][ e107 CMS - reflected xss in registration page
[ DATE ........ ][ 16.04.2012
[ AUTOHR ...... ][ http://hauntit.blogspot.com
[ SOFT LINK ... ][ http://e107.org
[ VERSION ..... ][
[ TESTED ON ... ][ LAMP
[ ----------------------------------------------------------------------- [
[ 1. What is this?
[ 2. What is the type of vulnerability?
[ 3. Where is bug :)
[ 4. More...
[--------------------------------------------[
[ 1. What is this?
This is very nice CMS, You should try it! ;)
[--------------------------------------------[
[ 2. What is the type of vulnerability?
Reflected XSS.
[--------------------------------------------[
[ 3. Where is bug :)
At registration page. Screens of attacks available at my blog.
[--------------------------------------------[
[ 4. More...
- http://hauntit.blogspot.com
- http://www.e107.org
- http://www.google.com
- http://portswigger.net
[
[--------------------------------------------[
[ Ask me about new projects @ mail. ;)
]
[ Best regards
[