Записи runcms
34 опубликованных записей вендора runcms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2007-5535Эксплойта нет | Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.runcms · runcms | Критическая10,0 | — | 1,5 % | 17 окт. 2007 г. |
33Наблюдать | CVE-2007-2539Proof of concept | The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadatruncms · runcms | Высокая7,8 | — | 7,9 % | 8 мая 2007 г. |
32Наблюдать | CVE-2007-6548Proof of concept | Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary Pruncms · runcms · CWE-94 | Высокая7,5 | — | 7,8 % | 27 дек. 2007 г. |
31Наблюдать | CVE-2007-2538Proof of concept | SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commaruncms · runcms | Высокая7,5 | — | 4,8 % | 8 мая 2007 г. |
31Наблюдать | CVE-2007-6544Proof of concept | Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameterruncms · runcms · CWE-89 | Высокая7,5 | — | 4,3 % | 27 дек. 2007 г. |
31Наблюдать | CVE-2006-1793Proof of concept | Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter truncms · runcms | Высокая7,6 | — | 3,6 % | 17 апр. 2006 г. |
31Наблюдать | CVE-2008-3354Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execruncms · newbb plus module · CWE-94 | Высокая7,5 | — | 2,5 % | 28 июл. 2008 г. |
31Наблюдать | CVE-2006-4667Эксплойта нет | Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter inruncms · runcms | Высокая7,5 | — | 2,5 % | 8 сент. 2006 г. |
31Наблюдать | CVE-2005-2691Эксплойта нет | includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attruncms · runcms | Высокая7,5 | — | 2,3 % | 24 авг. 2005 г. |
31Наблюдать | CVE-2008-0224Proof of concept | SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrruncms · runcms · CWE-89 | Высокая7,5 | — | 2,0 % | 10 янв. 2008 г. |
31Наблюдать | CVE-2008-2084Proof of concept | SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL comyarticles · myarticles · CWE-89 | Высокая7,5 | — | 2,0 % | 5 мая 2008 г. |
31Наблюдать | CVE-2006-0721Proof of concept | SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_useridruncms · runcms | Высокая7,5 | — | 1,7 % | 16 февр. 2006 г. |
30Наблюдать | CVE-2005-2692Эксплойта нет | Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addqueruncms · runcms | Высокая7,5 | — | 1,2 % | 24 авг. 2005 г. |
30Наблюдать | CVE-2007-6549Эксплойта нет | Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."runcms · runcms | Высокая7,5 | — | 1,1 % | 27 дек. 2007 г. |
30Наблюдать | CVE-2008-0878Proof of concept | SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQruncms · myannonces · CWE-89 | Высокая7,5 | — | 1,0 % | 21 февр. 2008 г. |
30Наблюдать | CVE-2008-1551Proof of concept | SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands viaruncms · photo module · CWE-89 | Высокая7,5 | — | 1,0 % | 31 мар. 2008 г. |
30Наблюдать | CVE-2009-2591Proof of concept | SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lie-xoopport · e-xoopport · CWE-89 | Высокая7,5 | — | 1,0 % | 24 июл. 2009 г. |
28Наблюдать | CVE-2006-0659Proof of concept | Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote runcms · runcms · CWE-94 | Средняя6,8 | — | 4,1 % | 13 февр. 2006 г. |
28Наблюдать | CVE-2007-6547Proof of concept | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change runcms · runcms | Средняя6,8 | — | 2,4 % | 27 дек. 2007 г. |
27Наблюдать | CVE-2008-1462Proof of concept | SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artruncms · runcms · CWE-89 | Средняя6,8 | — | 0,9 % | 24 мар. 2008 г. |
27Наблюдать | CVE-2008-7221Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for rruncms · runcms · CWE-352 | Средняя6,8 | — | 0,6 % | 14 сент. 2009 г. |
26Наблюдать | CVE-2007-6546Proof of concept | RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.runcms · runcms | Средняя6,4 | — | 2,7 % | 27 дек. 2007 г. |
26Наблюдать | CVE-2009-3814Эксплойта нет | Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Bruncms · runcms · CWE-94 | Средняя6,5 | — | 1,1 % | 27 окт. 2009 г. |
26Наблюдать | CVE-2009-3813Эксплойта нет | Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum paruncms · runcms · CWE-89 | Средняя6,5 | — | 0,9 % | 27 окт. 2009 г. |
26Наблюдать | CVE-2009-3804Proof of concept | Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL comruncms · runcms · CWE-89 | Средняя6,5 | — | 0,8 % | 27 окт. 2009 г. |
- CVE-2007-553540В плане
Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %runcms · runcms17 окт. 2007 г.
- CVE-2007-253933Наблюдать
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadat
ВысокаяCVSS 7,8Proof of conceptEPSS 8 %runcms · runcms8 мая 2007 г.
- CVE-2007-654832Наблюдать
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary P
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %runcms · runcms27 дек. 2007 г.
- CVE-2007-253831Наблюдать
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %runcms · runcms8 мая 2007 г.
- CVE-2007-654431Наблюдать
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %runcms · runcms27 дек. 2007 г.
- CVE-2006-179331Наблюдать
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter t
ВысокаяCVSS 7,6Proof of conceptEPSS 4 %runcms · runcms17 апр. 2006 г.
- CVE-2008-335431Наблюдать
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to exec
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %runcms · newbb plus module28 июл. 2008 г.
- CVE-2006-466731Наблюдать
Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %runcms · runcms8 сент. 2006 г.
- CVE-2005-269131Наблюдать
includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote att
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %runcms · runcms24 авг. 2005 г.
- CVE-2008-022431Наблюдать
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %runcms · runcms10 янв. 2008 г.
- CVE-2008-208431Наблюдать
SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL co
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %myarticles · myarticles5 мая 2008 г.
- CVE-2006-072131Наблюдать
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %runcms · runcms16 февр. 2006 г.
- CVE-2005-269230Наблюдать
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addque
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %runcms · runcms24 авг. 2005 г.
- CVE-2007-654930Наблюдать
Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %runcms · runcms27 дек. 2007 г.
- CVE-2008-087830Наблюдать
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %runcms · myannonces21 февр. 2008 г.
- CVE-2008-155130Наблюдать
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %runcms · photo module31 мар. 2008 г.
- CVE-2009-259130Наблюдать
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the li
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %e-xoopport · e-xoopport24 июл. 2009 г.
- CVE-2006-065928Наблюдать
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote
СредняяCVSS 6,8Proof of conceptEPSS 4 %runcms · runcms13 февр. 2006 г.
- CVE-2007-654728Наблюдать
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change
СредняяCVSS 6,8Proof of conceptEPSS 2 %runcms · runcms27 дек. 2007 г.
- CVE-2008-146227Наблюдать
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the art
СредняяCVSS 6,8Proof of conceptEPSS 1 %runcms · runcms24 мар. 2008 г.
- CVE-2008-722127Наблюдать
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for r
СредняяCVSS 6,8Эксплойта нетEPSS 1 %runcms · runcms14 сент. 2009 г.
- CVE-2007-654626Наблюдать
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
СредняяCVSS 6,4Proof of conceptEPSS 3 %runcms · runcms27 дек. 2007 г.
- CVE-2009-381426Наблюдать
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/B
СредняяCVSS 6,5Эксплойта нетEPSS 1 %runcms · runcms27 окт. 2009 г.
- CVE-2009-381326Наблюдать
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum pa
СредняяCVSS 6,5Эксплойта нетEPSS 1 %runcms · runcms27 окт. 2009 г.
- CVE-2009-380426Наблюдать
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL com
СредняяCVSS 6,5Proof of conceptEPSS 1 %runcms · runcms27 окт. 2009 г.