header-logo
Suggest Exploit
vendor:
RunCMS
by:
Alexandr Polyakov, Stas Svistunovich
N/A
CVSS
N/A
SQL Injection, XSS, PHP Include, Predictable session id
CWE
Product Name: RunCMS
Affected Version From: RunCMS 1.6
Affected Version To: RunCMS 1.6
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

RunCMS Vulnerabilities

RunCMS system has multiple security vulnerabilities including Blind SQL Injection, Stored XSS, Linked XSS, Image XSS, Predictable session id, Vulnerable password changing algorithm, and many PHP Injections in the Administrator panel.

Mitigation:

Source

Exploit-DB raw data: