CVE-2006-4757 (CNNVD-200609-218)
中文标题:
e107 多个SQL注入漏洞
英文标题:
Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated...
漏洞描述
中文描述:
e107 0.7.5的admin区段中存在多个SQL注入漏洞,远程认证的管理用户可以通过以下方式执行任意SQL命令:(a) links.php中的(1)linkopentype、(2)linkrender、(3)link_class和(4)link_id参数;(b)users.php中的(5) searchquery参数;以及(c)download.php中的(6) download_category_class参数。
英文描述:
Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| e107 | e107 | * | - | - |
cpe:2.3:a:e107:e107:*:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_10 | - | - |
cpe:2.3:a:e107:e107:0.6_10:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_11 | - | - |
cpe:2.3:a:e107:e107:0.6_11:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_12 | - | - |
cpe:2.3:a:e107:e107:0.6_12:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_13 | - | - |
cpe:2.3:a:e107:e107:0.6_13:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_14 | - | - |
cpe:2.3:a:e107:e107:0.6_14:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_15 | - | - |
cpe:2.3:a:e107:e107:0.6_15:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6_15a | - | - |
cpe:2.3:a:e107:e107:0.6_15a:*:*:*:*:*:*:*
|
| e107 | e107 | 0.7 | - | - |
cpe:2.3:a:e107:e107:0.7:*:*:*:*:*:*:*
|
| e107 | e107 | 0.7.1 | - | - |
cpe:2.3:a:e107:e107:0.7.1:*:*:*:*:*:*:*
|
| e107 | e107 | 0.7.2 | - | - |
cpe:2.3:a:e107:e107:0.7.2:*:*:*:*:*:*:*
|
| e107 | e107 | 0.7.3 | - | - |
cpe:2.3:a:e107:e107:0.7.3:*:*:*:*:*:*:*
|
| e107 | e107 | 0.7.4 | - | - |
cpe:2.3:a:e107:e107:0.7.4:*:*:*:*:*:*:*
|
| e107 | e107 | 0.545 | - | - |
cpe:2.3:a:e107:e107:0.545:*:*:*:*:*:*:*
|
| e107 | e107 | 0.547_beta | - | - |
cpe:2.3:a:e107:e107:0.547_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.548_beta | - | - |
cpe:2.3:a:e107:e107:0.548_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.549_beta | - | - |
cpe:2.3:a:e107:e107:0.549_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.551_beta | - | - |
cpe:2.3:a:e107:e107:0.551_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.552_beta | - | - |
cpe:2.3:a:e107:e107:0.552_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.553_beta | - | - |
cpe:2.3:a:e107:e107:0.553_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.554 | - | - |
cpe:2.3:a:e107:e107:0.554:*:*:*:*:*:*:*
|
| e107 | e107 | 0.554_beta | - | - |
cpe:2.3:a:e107:e107:0.554_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.555_beta | - | - |
cpe:2.3:a:e107:e107:0.555_beta:*:*:*:*:*:*:*
|
| e107 | e107 | 0.600 | - | - |
cpe:2.3:a:e107:e107:0.600:*:*:*:*:*:*:*
|
| e107 | e107 | 0.601 | - | - |
cpe:2.3:a:e107:e107:0.601:*:*:*:*:*:*:*
|
| e107 | e107 | 0.602 | - | - |
cpe:2.3:a:e107:e107:0.602:*:*:*:*:*:*:*
|
| e107 | e107 | 0.603 | - | - |
cpe:2.3:a:e107:e107:0.603:*:*:*:*:*:*:*
|
| e107 | e107 | 0.604 | - | - |
cpe:2.3:a:e107:e107:0.604:*:*:*:*:*:*:*
|
| e107 | e107 | 0.605 | - | - |
cpe:2.3:a:e107:e107:0.605:*:*:*:*:*:*:*
|
| e107 | e107 | 0.606 | - | - |
cpe:2.3:a:e107:e107:0.606:*:*:*:*:*:*:*
|
| e107 | e107 | 0.607 | - | - |
cpe:2.3:a:e107:e107:0.607:*:*:*:*:*:*:*
|
| e107 | e107 | 0.608 | - | - |
cpe:2.3:a:e107:e107:0.608:*:*:*:*:*:*:*
|
| e107 | e107 | 0.609 | - | - |
cpe:2.3:a:e107:e107:0.609:*:*:*:*:*:*:*
|
| e107 | e107 | 0.610 | - | - |
cpe:2.3:a:e107:e107:0.610:*:*:*:*:*:*:*
|
| e107 | e107 | 0.611 | - | - |
cpe:2.3:a:e107:e107:0.611:*:*:*:*:*:*:*
|
| e107 | e107 | 0.612 | - | - |
cpe:2.3:a:e107:e107:0.612:*:*:*:*:*:*:*
|
| e107 | e107 | 0.613 | - | - |
cpe:2.3:a:e107:e107:0.613:*:*:*:*:*:*:*
|
| e107 | e107 | 0.614 | - | - |
cpe:2.3:a:e107:e107:0.614:*:*:*:*:*:*:*
|
| e107 | e107 | 0.615 | - | - |
cpe:2.3:a:e107:e107:0.615:*:*:*:*:*:*:*
|
| e107 | e107 | 0.615a | - | - |
cpe:2.3:a:e107:e107:0.615a:*:*:*:*:*:*:*
|
| e107 | e107 | 0.616 | - | - |
cpe:2.3:a:e107:e107:0.616:*:*:*:*:*:*:*
|
| e107 | e107 | 0.617 | - | - |
cpe:2.3:a:e107:e107:0.617:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6171 | - | - |
cpe:2.3:a:e107:e107:0.6171:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6172 | - | - |
cpe:2.3:a:e107:e107:0.6172:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6173 | - | - |
cpe:2.3:a:e107:e107:0.6173:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6174 | - | - |
cpe:2.3:a:e107:e107:0.6174:*:*:*:*:*:*:*
|
| e107 | e107 | 0.6175 | - | - |
cpe:2.3:a:e107:e107:0.6175:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:H/Au:S/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2006-4757 |
2025-11-11 15:17:45 | 2025-11-11 07:32:37 |
| NVD | nvd_CVE-2006-4757 |
2025-11-11 14:51:51 | 2025-11-11 07:41:22 |
| CNNVD | cnnvd_CNNVD-200609-218 |
2025-11-11 15:08:53 | 2025-11-11 07:49:10 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> SQL注入
- cnnvd_id: 未提取 -> CNNVD-200609-218
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 4.6
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:H/Au:S/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 47
- data_sources: ['cve'] -> ['cve', 'nvd']