vendor:
RunCMS
by:
Alexandr Polyakov, Stas Svistunovich
N/A
CVSS
N/A
SQL Injection, XSS, PHP Include, Predictable session id
CWE
Product Name: RunCMS
Affected Version From: RunCMS 1.6
Affected Version To: RunCMS 1.6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
RunCMS Vulnerabilities
RunCMS system has multiple security vulnerabilities including Blind SQL Injection, Stored XSS, Linked XSS, Image XSS, Predictable session id, Vulnerable password changing algorithm, and many PHP Injections in the Administrator panel.