Back

CVE-2005-3521

SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.

Published: Nov 6, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
e107 e107 0.617
e107 e107 0.6171
e107 e107 0.6172

GitHub Security Advisory GHSA-v9hw-cwhg-vr8f

SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.63%

Top 26% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub