PT-2006-1715 · Runcms · Runcms

Published

2006-02-13

·

Updated

2011-09-08

·

CVE-2006-0659

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RunCMS versions 1.2 and earlier
Description The issue allows remote attackers to execute arbitrary code due to multiple PHP remote file include vulnerabilities. This is possible when register globals and allow url fopen are enabled. The vulnerability can be exploited via the bbPath[path] parameter in files such as class.forumposts.php and forumpollrenderer.php.
Recommendations For RunCMS versions 1.2 and earlier, consider disabling the register globals and allow url fopen settings to mitigate the risk of exploitation. As a temporary workaround, restrict access to the vulnerable files class.forumposts.php and forumpollrenderer.php until a patch is available. Avoid using the bbPath[path] parameter in affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0659

Affected Products

Runcms