e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating. NOTE: in the default installation, the e_BASE variable restricts the redirection to the same web site.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/418577/100/0/threaded | mailing list |
http://securityreason.com/securityalert/229 | third party advisory |
http://secunia.com/advisories/17890/ | exploit third party advisory vendor advisory |