7.5
CVSSv2

CVE-2007-6544

Published: 28/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in RunCMS prior to 1.6.1 allow remote malicious users to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.

Vulnerable Product Search on Vulmon Subscribe to Product

runcms runcms 1.6

Exploits

#/******************************************************************/ #/**** RUNCMS 16 BLIND SQL Injection Exploit get Admin Cookie *****/ #/******************************************************************/ #/*********** exploit get admin cookie that can be used *********/ #/*********** to login by pasting it into browser (Opera) *********/ ...
#/******************************************************************/ #/****** RUNCMS 16 BLIND SQL Injection Exploit + IDS evasion *****/ #/******************************************************************/ #/*********** exploit get hash of admin password *************/ #/*********** **************/ ...