{ "schema_version": "1.4.0", "id": "GHSA-mr3j-qx87-whmq", "modified": "2022-05-17T05:17:55Z", "published": "2022-05-17T05:17:55Z", "aliases": [ "CVE-2010-2098" ], "details": "Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks via the loginname parameter.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2098" }, { "type": "WEB", "url": "http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/usersettings.php?r1=11521&r2=11538" }, { "type": "WEB", "url": "http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/usersettings.php?r1=11538&r2=11541" }, { "type": "WEB", "url": "http://php-security.org/2010/05/15/mops-2010-029-cmsqlite-c-parameter-sql-injection-vulnerability/index.html" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-05-27T22:30:00Z" } }