e107 Website System Voting Manipulation Vulnerability
BID:15748
Info
e107 Website System Voting Manipulation Vulnerability
| Bugtraq ID: | 15748 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2005 12:00AM |
| Updated: | Dec 06 2005 12:00AM |
| Credit: | "Marc Ruef" <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
e107 e107 website system 0.6171 e107 e107 website system 0.617 e107 e107 website system 0.616 e107 e107 website system 0.603 e107 e107 website system 0.555 Beta e107 e107 website system 0.554 e107 e107 website system 0.545 e107 e107 website system 0.6 15a e107 e107 website system 0.6 15 e107 e107 website system 0.6 14 e107 e107 website system 0.6 13 e107 e107 website system 0.6 12 e107 e107 website system 0.6 11 e107 e107 website system 0.6 10 e107 e107 website system 0.6175 |
| Not Vulnerable: | |
Discussion
e107 Website System Voting Manipulation Vulnerability
e107 is prone to a vulnerability that could permit an attacker to vote multiple times.
An attacker can exploit this issue to vote positively or negatively for content multiple times. This will skew the expected poll results.
e107 is prone to a vulnerability that could permit an attacker to vote multiple times.
An attacker can exploit this issue to vote positively or negatively for content multiple times. This will skew the expected poll results.
Exploit / POC
e107 Website System Voting Manipulation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
e107 Website System Voting Manipulation Vulnerability
Solution:
Reports indicate this issue has been addressed in the latest CVS version; this has not been confirmed by Symantec.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reports indicate this issue has been addressed in the latest CVS version; this has not been confirmed by Symantec.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
e107 Website System Voting Manipulation Vulnerability
References:
References:
- e107 website system Homepage (e107.org)
- [scip_Advisory] e107 v0.6 rate.php manipulation ("Marc Ruef"
)