CVE-2008-0224
- EPSS 0.34%
- Published 10.01.2008 23:46:00
- Last modified 09.04.2025 00:30:58
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.
CVE-2007-6545
- EPSS 7.7%
- Published 28.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly r...
CVE-2007-6549
- EPSS 0.33%
- Published 28.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."
CVE-2007-6548
- EPSS 5.65%
- Published 28.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) footer parameters to modules/system/admin.php in a meta-generator action, (...
CVE-2007-6547
- EPSS 4.71%
- Published 28.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.
CVE-2007-6546
- EPSS 4.97%
- Published 28.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
CVE-2007-6544
- EPSS 2.96%
- Published 28.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) m...
- EPSS 0.39%
- Published 18.10.2007 00:17:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.
CVE-2007-2539
- EPSS 6.62%
- Published 09.05.2007 01:19:00
- Last modified 09.04.2025 00:30:58
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors.
CVE-2007-2538
- EPSS 2.71%
- Published 09.05.2007 01:19:00
- Last modified 09.04.2025 00:30:58
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array parameter.