CVE Vulnerabilities

CVE-2005-2691

Published: Aug 24, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.

Affected Software

Name Vendor Start Version End Version
Runcms Runcms 1.1 (including) 1.1 (including)
Runcms Runcms 1.1a (including) 1.1a (including)
Runcms Runcms 1.2 (including) 1.2 (including)

References