Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Runcms MEDIUM 6.5
CVE-2009-3804

Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 6.5
CVE-2009-3813

Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter t…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 6.5
CVE-2009-3814

Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" f…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 5.0
CVE-2009-3815

RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to m…

No fix yet
Fix from $1,600 2009-10-27
Runcms MEDIUM 6.8
CVE-2008-7221

Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests t…

Mitigation only
Fix from $1,600 2009-09-14
Myannonces HIGH 7.5
CVE-2009-2591

SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid paramet…

No fix yet
Fix from $1,950 2009-07-24
Newbb Plus Module HIGH 7.5
CVE-2008-3354

Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbit…

No fix yet
Fix from $1,950 2008-07-28
Photo Module HIGH 7.5
CVE-2008-1551

SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid …

No fix yet
Fix from $1,950 2008-03-31
Runcms MEDIUM 6.8
CVE-2008-1462

SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parame…

No fix yet
Fix from $1,600 2008-03-24
Myannonces HIGH 7.5
CVE-2008-0878

SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2008-02-21
Runcms HIGH 7.5
CVE-2008-0224

SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL c…

No fix yet
Fix from $1,950 2008-01-10
Runcms MEDIUM 5.0
CVE-2006-0875

Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid paramet…

No fix yet
Fix from $1,600 2006-02-24
Runcms HIGH 7.5
CVE-2005-2691

includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to…

Mitigation only
Fix from $1,950 2005-08-24
Runcms HIGH 7.5
CVE-2005-2692

Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2…

No fix yet
Fix from $1,950 2005-08-24