vendor:
RunCms
by:
trueend5
7.5
CVSS
HIGH
Remote Code Execution
Unknown
CWE
Product Name: RunCms
Affected Version From: RunCMS 1.6 Halloween, 1.5.x
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:runcms:runcms:1.6_halloween
Platforms Tested:
Unknown
RunCms`s Bug Yahoo! Crawler
The RunCms software is vulnerable to remote code execution due to a bug in the Yahoo! Crawler. This vulnerability allows an attacker to execute arbitrary code on the target system by sending a specially crafted packet.
Mitigation:
Update to a non-vulnerable version of RunCms.