Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6544 (RunCMS)

BugsAlert Home > CVE-2007-6544 (RunCMS)
 
 

Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6544

Learn more about CVE-2007-6544 (RunCMS)
 
Tags: cve-2007-6544 runcms

Related Items

      Bugtraq: [ENABLESECURITY] Apple's Mail.app stores your S/MIME encrypted emails in clear text

      Vuln: Ocean12 Contact Manager Pro 'DisplayFormat' Parameter Cross Site Scripting Vulnerability

      Vuln: Venalsur Booking Centre 'HotelID' Parameter SQL Injection Vulnerability

      CVE-2007-6612 (Mongrel)

      CVE-2008-2435 (housecall)

      VU#230505:Cisco IOS LPD buffer overflow vulnerability

      muCommander "credentials.xml" Information Disclosure

 

Pixel