Skip to content
Noroxi

runcms records

34 published records for vendor runcms.

All records

34 records
  • Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 2%

    runcms · runcmsOct 17, 2007

  • CVE-2007-2539
    33Monitor

    The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadat

    HighCVSS 7.8Proof of conceptEPSS 8%

    runcms · runcmsMay 8, 2007

  • CVE-2007-6548
    32Monitor

    Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary P

    HighCVSS 7.5Proof of conceptEPSS 8%

    runcms · runcmsDec 27, 2007

  • CVE-2007-2538
    31Monitor

    SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL comma

    HighCVSS 7.5Proof of conceptEPSS 5%

    runcms · runcmsMay 8, 2007

  • CVE-2007-6544
    31Monitor

    Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter

    HighCVSS 7.5Proof of conceptEPSS 4%

    runcms · runcmsDec 27, 2007

  • CVE-2006-1793
    31Monitor

    Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter t

    HighCVSS 7.6Proof of conceptEPSS 4%

    runcms · runcmsApr 17, 2006

  • CVE-2008-3354
    31Monitor

    Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to exec

    HighCVSS 7.5Proof of conceptEPSS 3%

    runcms · newbb plus moduleJul 28, 2008

  • CVE-2006-4667
    31Monitor

    Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in

    HighCVSS 7.5No exploitEPSS 3%

    runcms · runcmsSep 8, 2006

  • CVE-2005-2691
    31Monitor

    includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote att

    HighCVSS 7.5No exploitEPSS 2%

    runcms · runcmsAug 24, 2005

  • CVE-2008-0224
    31Monitor

    SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitr

    HighCVSS 7.5Proof of conceptEPSS 2%

    runcms · runcmsJan 10, 2008

  • CVE-2008-2084
    31Monitor

    SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL co

    HighCVSS 7.5Proof of conceptEPSS 2%

    myarticles · myarticlesMay 5, 2008

  • CVE-2006-0721
    31Monitor

    SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid

    HighCVSS 7.5Proof of conceptEPSS 2%

    runcms · runcmsFeb 16, 2006

  • CVE-2005-2692
    30Monitor

    Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addque

    HighCVSS 7.5No exploitEPSS 1%

    runcms · runcmsAug 24, 2005

  • CVE-2007-6549
    30Monitor

    Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."

    HighCVSS 7.5No exploitEPSS 1%

    runcms · runcmsDec 27, 2007

  • CVE-2008-0878
    30Monitor

    SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQ

    HighCVSS 7.5Proof of conceptEPSS 1%

    runcms · myannoncesFeb 21, 2008

  • CVE-2008-1551
    30Monitor

    SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via

    HighCVSS 7.5Proof of conceptEPSS 1%

    runcms · photo moduleMar 31, 2008

  • CVE-2009-2591
    30Monitor

    SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the li

    HighCVSS 7.5Proof of conceptEPSS 1%

    e-xoopport · e-xoopportJul 24, 2009

  • CVE-2006-0659
    28Monitor

    Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote

    MediumCVSS 6.8Proof of conceptEPSS 4%

    runcms · runcmsFeb 13, 2006

  • CVE-2007-6547
    28Monitor

    RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change

    MediumCVSS 6.8Proof of conceptEPSS 2%

    runcms · runcmsDec 27, 2007

  • CVE-2008-1462
    27Monitor

    SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the art

    MediumCVSS 6.8Proof of conceptEPSS 1%

    runcms · runcmsMar 24, 2008

  • CVE-2008-7221
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for r

    MediumCVSS 6.8No exploitEPSS 1%

    runcms · runcmsSep 14, 2009

  • CVE-2007-6546
    26Monitor

    RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

    MediumCVSS 6.4Proof of conceptEPSS 3%

    runcms · runcmsDec 27, 2007

  • CVE-2009-3814
    26Monitor

    Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/B

    MediumCVSS 6.5No exploitEPSS 1%

    runcms · runcmsOct 27, 2009

  • CVE-2009-3813
    26Monitor

    Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum pa

    MediumCVSS 6.5No exploitEPSS 1%

    runcms · runcmsOct 27, 2009

  • CVE-2009-3804
    26Monitor

    Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL com

    MediumCVSS 6.5Proof of conceptEPSS 1%

    runcms · runcmsOct 27, 2009