runcms kayıtları
runcms üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2007-5535İstismar yok | Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.runcms · runcms | Kritik10,0 | — | %1,5 | 17 Eki 2007 |
33İzleyin | CVE-2007-2539Kavram kanıtı | The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadatruncms · runcms | Yüksek7,8 | — | %7,9 | 8 May 2007 |
32İzleyin | CVE-2007-6548Kavram kanıtı | Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary Pruncms · runcms · CWE-94 | Yüksek7,5 | — | %7,8 | 27 Ara 2007 |
31İzleyin | CVE-2007-2538Kavram kanıtı | SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commaruncms · runcms | Yüksek7,5 | — | %4,8 | 8 May 2007 |
31İzleyin | CVE-2007-6544Kavram kanıtı | Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameterruncms · runcms · CWE-89 | Yüksek7,5 | — | %4,3 | 27 Ara 2007 |
31İzleyin | CVE-2006-1793Kavram kanıtı | Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter truncms · runcms | Yüksek7,6 | — | %3,6 | 17 Nis 2006 |
31İzleyin | CVE-2008-3354Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execruncms · newbb plus module · CWE-94 | Yüksek7,5 | — | %2,5 | 28 Tem 2008 |
31İzleyin | CVE-2006-4667İstismar yok | Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter inruncms · runcms | Yüksek7,5 | — | %2,5 | 8 Eyl 2006 |
31İzleyin | CVE-2005-2691İstismar yok | includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attruncms · runcms | Yüksek7,5 | — | %2,3 | 24 Ağu 2005 |
31İzleyin | CVE-2008-0224Kavram kanıtı | SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrruncms · runcms · CWE-89 | Yüksek7,5 | — | %2,0 | 10 Oca 2008 |
31İzleyin | CVE-2008-2084Kavram kanıtı | SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL comyarticles · myarticles · CWE-89 | Yüksek7,5 | — | %2,0 | 5 May 2008 |
31İzleyin | CVE-2006-0721Kavram kanıtı | SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_useridruncms · runcms | Yüksek7,5 | — | %1,7 | 16 Şub 2006 |
30İzleyin | CVE-2005-2692İstismar yok | Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addqueruncms · runcms | Yüksek7,5 | — | %1,2 | 24 Ağu 2005 |
30İzleyin | CVE-2007-6549İstismar yok | Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."runcms · runcms | Yüksek7,5 | — | %1,1 | 27 Ara 2007 |
30İzleyin | CVE-2008-0878Kavram kanıtı | SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQruncms · myannonces · CWE-89 | Yüksek7,5 | — | %1,0 | 21 Şub 2008 |
30İzleyin | CVE-2008-1551Kavram kanıtı | SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands viaruncms · photo module · CWE-89 | Yüksek7,5 | — | %1,0 | 31 Mar 2008 |
30İzleyin | CVE-2009-2591Kavram kanıtı | SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lie-xoopport · e-xoopport · CWE-89 | Yüksek7,5 | — | %1,0 | 24 Tem 2009 |
28İzleyin | CVE-2006-0659Kavram kanıtı | Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote runcms · runcms · CWE-94 | Orta6,8 | — | %4,1 | 13 Şub 2006 |
28İzleyin | CVE-2007-6547Kavram kanıtı | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change runcms · runcms | Orta6,8 | — | %2,4 | 27 Ara 2007 |
27İzleyin | CVE-2008-1462Kavram kanıtı | SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artruncms · runcms · CWE-89 | Orta6,8 | — | %0,9 | 24 Mar 2008 |
27İzleyin | CVE-2008-7221İstismar yok | Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for rruncms · runcms · CWE-352 | Orta6,8 | — | %0,6 | 14 Eyl 2009 |
26İzleyin | CVE-2007-6546Kavram kanıtı | RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.runcms · runcms | Orta6,4 | — | %2,7 | 27 Ara 2007 |
26İzleyin | CVE-2009-3814İstismar yok | Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Bruncms · runcms · CWE-94 | Orta6,5 | — | %1,1 | 27 Eki 2009 |
26İzleyin | CVE-2009-3813İstismar yok | Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum paruncms · runcms · CWE-89 | Orta6,5 | — | %0,9 | 27 Eki 2009 |
26İzleyin | CVE-2009-3804Kavram kanıtı | Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL comruncms · runcms · CWE-89 | Orta6,5 | — | %0,8 | 27 Eki 2009 |
- CVE-2007-553540Planlayın
Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2runcms · runcms17 Eki 2007
- CVE-2007-253933İzleyin
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadat
YüksekCVSS 7,8Kavram kanıtıEPSS %8runcms · runcms8 May 2007
- CVE-2007-654832İzleyin
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary P
YüksekCVSS 7,5Kavram kanıtıEPSS %8runcms · runcms27 Ara 2007
- CVE-2007-253831İzleyin
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5Kavram kanıtıEPSS %5runcms · runcms8 May 2007
- CVE-2007-654431İzleyin
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %4runcms · runcms27 Ara 2007
- CVE-2006-179331İzleyin
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter t
YüksekCVSS 7,6Kavram kanıtıEPSS %4runcms · runcms17 Nis 2006
- CVE-2008-335431İzleyin
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to exec
YüksekCVSS 7,5Kavram kanıtıEPSS %3runcms · newbb plus module28 Tem 2008
- CVE-2006-466731İzleyin
Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in
YüksekCVSS 7,5İstismar yokEPSS %3runcms · runcms8 Eyl 2006
- CVE-2005-269131İzleyin
includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote att
YüksekCVSS 7,5İstismar yokEPSS %2runcms · runcms24 Ağu 2005
- CVE-2008-022431İzleyin
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitr
YüksekCVSS 7,5Kavram kanıtıEPSS %2runcms · runcms10 Oca 2008
- CVE-2008-208431İzleyin
SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL co
YüksekCVSS 7,5Kavram kanıtıEPSS %2myarticles · myarticles5 May 2008
- CVE-2006-072131İzleyin
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid
YüksekCVSS 7,5Kavram kanıtıEPSS %2runcms · runcms16 Şub 2006
- CVE-2005-269230İzleyin
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addque
YüksekCVSS 7,5İstismar yokEPSS %1runcms · runcms24 Ağu 2005
- CVE-2007-654930İzleyin
Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."
YüksekCVSS 7,5İstismar yokEPSS %1runcms · runcms27 Ara 2007
- CVE-2008-087830İzleyin
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %1runcms · myannonces21 Şub 2008
- CVE-2008-155130İzleyin
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1runcms · photo module31 Mar 2008
- CVE-2009-259130İzleyin
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the li
YüksekCVSS 7,5Kavram kanıtıEPSS %1e-xoopport · e-xoopport24 Tem 2009
- CVE-2006-065928İzleyin
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote
OrtaCVSS 6,8Kavram kanıtıEPSS %4runcms · runcms13 Şub 2006
- CVE-2007-654728İzleyin
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change
OrtaCVSS 6,8Kavram kanıtıEPSS %2runcms · runcms27 Ara 2007
- CVE-2008-146227İzleyin
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the art
OrtaCVSS 6,8Kavram kanıtıEPSS %1runcms · runcms24 Mar 2008
- CVE-2008-722127İzleyin
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for r
OrtaCVSS 6,8İstismar yokEPSS %1runcms · runcms14 Eyl 2009
- CVE-2007-654626İzleyin
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
OrtaCVSS 6,4Kavram kanıtıEPSS %3runcms · runcms27 Ara 2007
- CVE-2009-381426İzleyin
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/B
OrtaCVSS 6,5İstismar yokEPSS %1runcms · runcms27 Eki 2009
- CVE-2009-381326İzleyin
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum pa
OrtaCVSS 6,5İstismar yokEPSS %1runcms · runcms27 Eki 2009
- CVE-2009-380426İzleyin
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL com
OrtaCVSS 6,5Kavram kanıtıEPSS %1runcms · runcms27 Eki 2009