vendor:
RUNCMS
by:
Alexandr "Sh2kerr" Polyakov
7.5
CVSS
HIGH
Blind SQL Injection
CWE
Product Name: RUNCMS
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
RUNCMS 1.6 Blind SQL Injection Exploit + IDS evasion
This exploit allows an attacker to inject SQL code in various modules of RUNCMS 1.6, including mydownloads/brokenfile.php, mydownloads/visit.php, mydownloads/ratefile.php, mylinks/ratelink.php, and mylinks/modlink.php. By exploiting this vulnerability, the attacker can retrieve the hash of the admin password.
Mitigation:
Update RUNCMS to a newer version that fixes the SQL injection vulnerability.