PT-2006-1715 · Runcms · Runcms
Published
2006-02-13
·
Updated
2011-09-08
·
CVE-2006-0659
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RunCMS versions 1.2 and earlier
Description
The issue allows remote attackers to execute arbitrary code due to multiple PHP remote file include vulnerabilities. This is possible when register globals and allow url fopen are enabled. The vulnerability can be exploited via the
bbPath[path] parameter in files such as class.forumposts.php and forumpollrenderer.php.Recommendations
For RunCMS versions 1.2 and earlier, consider disabling the register globals and allow url fopen settings to mitigate the risk of exploitation. As a temporary workaround, restrict access to the vulnerable files class.forumposts.php and forumpollrenderer.php until a patch is available. Avoid using the
bbPath[path] parameter in affected API endpoints until the issue is resolved.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Runcms