Description
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
Remediation
References
Related Vulnerabilities
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-4782)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.36)
MySQL Numeric Errors Vulnerability (CVE-2006-3486)
WordPress Plugin Product Input Fields for WooCommerce Arbitrary File Download (1.2.6)
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9456)