e107 0.7.5 - 'Subject' HTML Injection

EDB-ID:

28078


Platform:

PHP

Published:

2006-06-21

source: http://www.securityfocus.com/bid/18560/info

The e107 CMS is prone to an HTML-injection vulnerability.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site when the inserted data is viewed.

In Submit comment:
Subject: '><script>alert(/XSS/)</script>