PT-2009-6040 · Runcms · Runcms

Published

2009-10-27

·

Updated

2009-10-28

·

CVE-2009-3813

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RunCMS version 2M1
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This can be achieved via the forum parameter to "modules/forum/post.php" and possibly the forum id variable to "modules/forum/class/class.permissions.php".
Recommendations For RunCMS version 2M1, consider restricting access to the modules/forum/post.php and modules/forum/class/class.permissions.php files until a patch is available. As a temporary workaround, avoid using the forum parameter and the forum id variable in the affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3813

Affected Products

Runcms