CVE Database · CVE-2010-2098
CVSS v3.1
N/A
EPSS
1.05%
Published
May 27, 2010
Modified
Apr 28, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks via the loginname parameter.
Affected Products (63)
References (6)
...and 13 more