runcms records
34 published records for vendor runcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 15
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2007-5535No exploit | Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.runcms · runcms | Critical10.0 | — | 1.5% | Oct 17, 2007 |
33Monitor | CVE-2007-2539Proof of concept | The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadatruncms · runcms | High7.8 | — | 7.9% | May 8, 2007 |
32Monitor | CVE-2007-6548Proof of concept | Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary Pruncms · runcms · CWE-94 | High7.5 | — | 7.8% | Dec 27, 2007 |
31Monitor | CVE-2007-2538Proof of concept | SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commaruncms · runcms | High7.5 | — | 4.8% | May 8, 2007 |
31Monitor | CVE-2007-6544Proof of concept | Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameterruncms · runcms · CWE-89 | High7.5 | — | 4.3% | Dec 27, 2007 |
31Monitor | CVE-2006-1793Proof of concept | Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter truncms · runcms | High7.6 | — | 3.6% | Apr 17, 2006 |
31Monitor | CVE-2008-3354Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execruncms · newbb plus module · CWE-94 | High7.5 | — | 2.5% | Jul 28, 2008 |
31Monitor | CVE-2006-4667No exploit | Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter inruncms · runcms | High7.5 | — | 2.5% | Sep 8, 2006 |
31Monitor | CVE-2005-2691No exploit | includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attruncms · runcms | High7.5 | — | 2.3% | Aug 24, 2005 |
31Monitor | CVE-2008-0224Proof of concept | SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrruncms · runcms · CWE-89 | High7.5 | — | 2.0% | Jan 10, 2008 |
31Monitor | CVE-2008-2084Proof of concept | SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL comyarticles · myarticles · CWE-89 | High7.5 | — | 2.0% | May 5, 2008 |
31Monitor | CVE-2006-0721Proof of concept | SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_useridruncms · runcms | High7.5 | — | 1.7% | Feb 16, 2006 |
30Monitor | CVE-2005-2692No exploit | Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addqueruncms · runcms | High7.5 | — | 1.2% | Aug 24, 2005 |
30Monitor | CVE-2007-6549No exploit | Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."runcms · runcms | High7.5 | — | 1.1% | Dec 27, 2007 |
30Monitor | CVE-2008-0878Proof of concept | SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQruncms · myannonces · CWE-89 | High7.5 | — | 1.0% | Feb 21, 2008 |
30Monitor | CVE-2008-1551Proof of concept | SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands viaruncms · photo module · CWE-89 | High7.5 | — | 1.0% | Mar 31, 2008 |
30Monitor | CVE-2009-2591Proof of concept | SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lie-xoopport · e-xoopport · CWE-89 | High7.5 | — | 1.0% | Jul 24, 2009 |
28Monitor | CVE-2006-0659Proof of concept | Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote runcms · runcms · CWE-94 | Medium6.8 | — | 4.1% | Feb 13, 2006 |
28Monitor | CVE-2007-6547Proof of concept | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change runcms · runcms | Medium6.8 | — | 2.4% | Dec 27, 2007 |
27Monitor | CVE-2008-1462Proof of concept | SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artruncms · runcms · CWE-89 | Medium6.8 | — | 0.9% | Mar 24, 2008 |
27Monitor | CVE-2008-7221No exploit | Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for rruncms · runcms · CWE-352 | Medium6.8 | — | 0.6% | Sep 14, 2009 |
26Monitor | CVE-2007-6546Proof of concept | RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.runcms · runcms | Medium6.4 | — | 2.7% | Dec 27, 2007 |
26Monitor | CVE-2009-3814No exploit | Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Bruncms · runcms · CWE-94 | Medium6.5 | — | 1.1% | Oct 27, 2009 |
26Monitor | CVE-2009-3813No exploit | Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum paruncms · runcms · CWE-89 | Medium6.5 | — | 0.9% | Oct 27, 2009 |
26Monitor | CVE-2009-3804Proof of concept | Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL comruncms · runcms · CWE-89 | Medium6.5 | — | 0.8% | Oct 27, 2009 |
- CVE-2007-553540Plan
Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%runcms · runcmsOct 17, 2007
- CVE-2007-253933Monitor
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadat
HighCVSS 7.8Proof of conceptEPSS 8%runcms · runcmsMay 8, 2007
- CVE-2007-654832Monitor
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary P
HighCVSS 7.5Proof of conceptEPSS 8%runcms · runcmsDec 27, 2007
- CVE-2007-253831Monitor
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5Proof of conceptEPSS 5%runcms · runcmsMay 8, 2007
- CVE-2007-654431Monitor
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter
HighCVSS 7.5Proof of conceptEPSS 4%runcms · runcmsDec 27, 2007
- CVE-2006-179331Monitor
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter t
HighCVSS 7.6Proof of conceptEPSS 4%runcms · runcmsApr 17, 2006
- CVE-2008-335431Monitor
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to exec
HighCVSS 7.5Proof of conceptEPSS 3%runcms · newbb plus moduleJul 28, 2008
- CVE-2006-466731Monitor
Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in
HighCVSS 7.5No exploitEPSS 3%runcms · runcmsSep 8, 2006
- CVE-2005-269131Monitor
includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote att
HighCVSS 7.5No exploitEPSS 2%runcms · runcmsAug 24, 2005
- CVE-2008-022431Monitor
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitr
HighCVSS 7.5Proof of conceptEPSS 2%runcms · runcmsJan 10, 2008
- CVE-2008-208431Monitor
SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL co
HighCVSS 7.5Proof of conceptEPSS 2%myarticles · myarticlesMay 5, 2008
- CVE-2006-072131Monitor
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid
HighCVSS 7.5Proof of conceptEPSS 2%runcms · runcmsFeb 16, 2006
- CVE-2005-269230Monitor
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addque
HighCVSS 7.5No exploitEPSS 1%runcms · runcmsAug 24, 2005
- CVE-2007-654930Monitor
Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."
HighCVSS 7.5No exploitEPSS 1%runcms · runcmsDec 27, 2007
- CVE-2008-087830Monitor
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQ
HighCVSS 7.5Proof of conceptEPSS 1%runcms · myannoncesFeb 21, 2008
- CVE-2008-155130Monitor
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%runcms · photo moduleMar 31, 2008
- CVE-2009-259130Monitor
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the li
HighCVSS 7.5Proof of conceptEPSS 1%e-xoopport · e-xoopportJul 24, 2009
- CVE-2006-065928Monitor
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote
MediumCVSS 6.8Proof of conceptEPSS 4%runcms · runcmsFeb 13, 2006
- CVE-2007-654728Monitor
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change
MediumCVSS 6.8Proof of conceptEPSS 2%runcms · runcmsDec 27, 2007
- CVE-2008-146227Monitor
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the art
MediumCVSS 6.8Proof of conceptEPSS 1%runcms · runcmsMar 24, 2008
- CVE-2008-722127Monitor
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for r
MediumCVSS 6.8No exploitEPSS 1%runcms · runcmsSep 14, 2009
- CVE-2007-654626Monitor
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
MediumCVSS 6.4Proof of conceptEPSS 3%runcms · runcmsDec 27, 2007
- CVE-2009-381426Monitor
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/B
MediumCVSS 6.5No exploitEPSS 1%runcms · runcmsOct 27, 2009
- CVE-2009-381326Monitor
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum pa
MediumCVSS 6.5No exploitEPSS 1%runcms · runcmsOct 27, 2009
- CVE-2009-380426Monitor
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL com
MediumCVSS 6.5Proof of conceptEPSS 1%runcms · runcmsOct 27, 2009