4.3
CVSSv2

CVE-2007-6545

Published: 28/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in RunCMS prior to 1.6.1 allow remote malicious users to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.

Vulnerable Product Search on Vulmon Subscribe to Product

runcms runcms

Exploits

Digital Security Research Group Advisory Application: RunCMS Versions Affected: RunCMS 16 Vendor URL: wwwruncmsorg Bugs: SQL Injections, XSS, PHP Include, Predictable session id, etc Exploits: Aviable Reported: 141 ...