Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2006-1216

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown

CVE-2006-0875

Disclosure Date: February 24, 2006 (last updated February 22, 2025)
Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.
0
Attacker Value
Unknown

CVE-2006-0721

Disclosure Date: February 16, 2006 (last updated February 22, 2025)
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.
0
Attacker Value
Unknown

CVE-2005-2691

Disclosure Date: August 24, 2005 (last updated February 22, 2025)
includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.
0
Attacker Value
Unknown

CVE-2005-2692

Disclosure Date: August 24, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2) subquery parameters to the newbb plus module, the forum parameter to (3) newtopic.php, (4) edit.php, or (5) reply.php in the newbb plus module, or (6) the msg_id parameter to print.php in the messages module.
0