İçeriğe atla
Noroxi

runcms kayıtları

runcms üreticisine ait 34 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
15
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

34 kayıt
  • CVE-2007-5535
    40Planlayın

    Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.

    KritikCVSS 10,0İstismar yokEPSS %2

    runcms · runcms17 Eki 2007

  • CVE-2007-2539
    33İzleyin

    The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadat

    YüksekCVSS 7,8Kavram kanıtıEPSS %8

    runcms · runcms8 May 2007

  • CVE-2007-6548
    32İzleyin

    Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary P

    YüksekCVSS 7,5Kavram kanıtıEPSS %8

    runcms · runcms27 Ara 2007

  • CVE-2007-2538
    31İzleyin

    SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL comma

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    runcms · runcms8 May 2007

  • CVE-2007-6544
    31İzleyin

    Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    runcms · runcms27 Ara 2007

  • CVE-2006-1793
    31İzleyin

    Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter t

    YüksekCVSS 7,6Kavram kanıtıEPSS %4

    runcms · runcms17 Nis 2006

  • CVE-2008-3354
    31İzleyin

    Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to exec

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    runcms · newbb plus module28 Tem 2008

  • CVE-2006-4667
    31İzleyin

    Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in

    YüksekCVSS 7,5İstismar yokEPSS %3

    runcms · runcms8 Eyl 2006

  • CVE-2005-2691
    31İzleyin

    includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote att

    YüksekCVSS 7,5İstismar yokEPSS %2

    runcms · runcms24 Ağu 2005

  • CVE-2008-0224
    31İzleyin

    SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitr

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    runcms · runcms10 Oca 2008

  • CVE-2008-2084
    31İzleyin

    SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL co

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    myarticles · myarticles5 May 2008

  • CVE-2006-0721
    31İzleyin

    SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    runcms · runcms16 Şub 2006

  • CVE-2005-2692
    30İzleyin

    Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addque

    YüksekCVSS 7,5İstismar yokEPSS %1

    runcms · runcms24 Ağu 2005

  • CVE-2007-6549
    30İzleyin

    Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."

    YüksekCVSS 7,5İstismar yokEPSS %1

    runcms · runcms27 Ara 2007

  • CVE-2008-0878
    30İzleyin

    SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQ

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    runcms · myannonces21 Şub 2008

  • CVE-2008-1551
    30İzleyin

    SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    runcms · photo module31 Mar 2008

  • CVE-2009-2591
    30İzleyin

    SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the li

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    e-xoopport · e-xoopport24 Tem 2009

  • CVE-2006-0659
    28İzleyin

    Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote

    OrtaCVSS 6,8Kavram kanıtıEPSS %4

    runcms · runcms13 Şub 2006

  • CVE-2007-6547
    28İzleyin

    RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    runcms · runcms27 Ara 2007

  • CVE-2008-1462
    27İzleyin

    SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the art

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    runcms · runcms24 Mar 2008

  • CVE-2008-7221
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for r

    OrtaCVSS 6,8İstismar yokEPSS %1

    runcms · runcms14 Eyl 2009

  • CVE-2007-6546
    26İzleyin

    RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

    OrtaCVSS 6,4Kavram kanıtıEPSS %3

    runcms · runcms27 Ara 2007

  • CVE-2009-3814
    26İzleyin

    Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/B

    OrtaCVSS 6,5İstismar yokEPSS %1

    runcms · runcms27 Eki 2009

  • CVE-2009-3813
    26İzleyin

    Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum pa

    OrtaCVSS 6,5İstismar yokEPSS %1

    runcms · runcms27 Eki 2009

  • CVE-2009-3804
    26İzleyin

    Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL com

    OrtaCVSS 6,5Kavram kanıtıEPSS %1

    runcms · runcms27 Eki 2009