Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Runcms MEDIUM 6.5
CVE-2009-3804

Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 6.5
CVE-2009-3813

Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter t…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 6.5
CVE-2009-3814

Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" f…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 5.0
CVE-2009-3815

RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to m…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 6.8
CVE-2008-7221

Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests t…

Mitigation only
Fix from $1,600 2009-09-14
Myannonces HIGH 7.5
CVE-2009-2591

SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid paramet…

No fix yet
Fix from $1,950 2009-07-24
Newbb Plus Module HIGH 7.5
CVE-2008-3354

Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbit…

No fix yet
Fix from $1,950 2008-07-28
Photo Module HIGH 7.5
CVE-2008-1551

SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid …

No fix yet
Fix from $1,950 2008-03-31
Runcms MEDIUM 6.8
CVE-2008-1462

SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parame…

No fix yet
Fix from $1,600 2008-03-24
Myannonces HIGH 7.5
CVE-2008-0878

SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2008-02-21
Runcms HIGH 7.5
CVE-2008-0224

SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL c…

No fix yet
Fix from $1,950 2008-01-10
Runcms HIGH 7.5
CVE-2007-6544

Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) b…

Patch available
Fix from $1,950 2007-12-28
Runcms HIGH 7.5
CVE-2007-6548EPSS 8%

Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code v…

Fix: after 1.6
Fix from $1,950 2007-12-28
Runcms HIGH 7.5
CVE-2007-6549

Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."

Fix: after 1.6
Fix from $1,950 2007-12-28
Runcms MEDIUM 6.8
CVE-2007-6547

RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords…

Fix: after 1.6
Fix from $1,600 2007-12-28
Runcms MEDIUM 6.4
CVE-2007-6546

RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

Fix: after 1.6
Fix from $1,600 2007-12-28
Runcms HIGH 10.0
CVE-2007-5535

Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.

Patch available
Fix from $1,950 2007-10-18
Runcms HIGH 7.8
CVE-2007-2539EPSS 8%

The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via un…

Fix: after 1.5.2
Fix from $1,950 2007-05-09
Runcms HIGH 7.5
CVE-2007-2538

SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via t…

Fix: after 1.5.2
Fix from $1,950 2007-05-09
Runcms HIGH 7.5
CVE-2006-4667

Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in (a) clas…

Patch available
Fix from $1,950 2006-09-09
Runcms HIGH 7.6
CVE-2006-1793

Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) cla…

Fix: after 1.2
Fix from $1,950 2006-04-17
Runcms MEDIUM 5.0
CVE-2006-0875

Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid paramet…

No fix yet
Fix from $1,600 2006-02-24
Runcms HIGH 7.5
CVE-2006-0721

SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid paramete…

Patch available
Fix from $1,950 2006-02-16
Runcms MEDIUM 6.8
CVE-2006-0659

Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers…

Fix: after 1.2
Fix from $1,600 2006-02-13
Runcms HIGH 7.5
CVE-2005-2691

includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to…

Mitigation only
Fix from $1,950 2005-08-24
Runcms HIGH 7.5
CVE-2005-2692

Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2…

No fix yet
Fix from $1,950 2005-08-24