Перейти к содержимому
Noroxi

Записи runcms

34 опубликованных записей вендора runcms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
15
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

34 записей
  • CVE-2007-5535
    40В плане

    Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    runcms · runcms17 окт. 2007 г.

  • CVE-2007-2539
    33Наблюдать

    The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadat

    ВысокаяCVSS 7,8Proof of conceptEPSS 8 %

    runcms · runcms8 мая 2007 г.

  • CVE-2007-6548
    32Наблюдать

    Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary P

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    runcms · runcms27 дек. 2007 г.

  • CVE-2007-2538
    31Наблюдать

    SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL comma

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    runcms · runcms8 мая 2007 г.

  • CVE-2007-6544
    31Наблюдать

    Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter

    ВысокаяCVSS 7,5Proof of conceptEPSS 4 %

    runcms · runcms27 дек. 2007 г.

  • CVE-2006-1793
    31Наблюдать

    Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter t

    ВысокаяCVSS 7,6Proof of conceptEPSS 4 %

    runcms · runcms17 апр. 2006 г.

  • CVE-2008-3354
    31Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to exec

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    runcms · newbb plus module28 июл. 2008 г.

  • CVE-2006-4667
    31Наблюдать

    Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    runcms · runcms8 сент. 2006 г.

  • CVE-2005-2691
    31Наблюдать

    includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote att

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    runcms · runcms24 авг. 2005 г.

  • CVE-2008-0224
    31Наблюдать

    SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitr

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    runcms · runcms10 янв. 2008 г.

  • CVE-2008-2084
    31Наблюдать

    SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL co

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    myarticles · myarticles5 мая 2008 г.

  • CVE-2006-0721
    31Наблюдать

    SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    runcms · runcms16 февр. 2006 г.

  • CVE-2005-2692
    30Наблюдать

    Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addque

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    runcms · runcms24 авг. 2005 г.

  • CVE-2007-6549
    30Наблюдать

    Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    runcms · runcms27 дек. 2007 г.

  • CVE-2008-0878
    30Наблюдать

    SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQ

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    runcms · myannonces21 февр. 2008 г.

  • CVE-2008-1551
    30Наблюдать

    SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    runcms · photo module31 мар. 2008 г.

  • CVE-2009-2591
    30Наблюдать

    SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the li

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    e-xoopport · e-xoopport24 июл. 2009 г.

  • CVE-2006-0659
    28Наблюдать

    Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote

    СредняяCVSS 6,8Proof of conceptEPSS 4 %

    runcms · runcms13 февр. 2006 г.

  • CVE-2007-6547
    28Наблюдать

    RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    runcms · runcms27 дек. 2007 г.

  • CVE-2008-1462
    27Наблюдать

    SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the art

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    runcms · runcms24 мар. 2008 г.

  • CVE-2008-7221
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for r

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    runcms · runcms14 сент. 2009 г.

  • CVE-2007-6546
    26Наблюдать

    RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

    СредняяCVSS 6,4Proof of conceptEPSS 3 %

    runcms · runcms27 дек. 2007 г.

  • CVE-2009-3814
    26Наблюдать

    Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/B

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    runcms · runcms27 окт. 2009 г.

  • CVE-2009-3813
    26Наблюдать

    Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum pa

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    runcms · runcms27 окт. 2009 г.

  • CVE-2009-3804
    26Наблюдать

    Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL com

    СредняяCVSS 6,5Proof of conceptEPSS 1 %

    runcms · runcms27 окт. 2009 г.