PT-2007-7380 · Runcms · Runcms
Alexandr Polyakov
+1
·
Published
2007-12-28
·
Updated
2018-10-15
·
CVE-2007-6548
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RunCMS versions prior to 1.6.1
Description
The issue allows remote authenticated administrators to inject arbitrary PHP code via several parameters in different modules, including
header and footer parameters to modules/system/admin.php, disclaimer parameters to various modules, and the intro parameter to modules/sections/admin/index.php. These injections lead to PHP sequences being written into cache files within the modules directory, potentially allowing for code execution.Recommendations
For RunCMS versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable parameters and modules, such as disabling the
header and footer parameters in modules/system/admin.php, and avoiding the use of disclaimer parameters in affected modules until the update is applied. Additionally, restrict write access to cache files in the modules directory to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Runcms