SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.
| Software | From | Fixed in |
|---|---|---|
| e107 / e107 | 0.6172 | 0.6172.x |
| e107 / e107 | 0.617 | 0.617.x |
| e107 / e107 | 0.6171 | 0.6171.x |