Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-6545

Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.077
EPSS Ranking 91.4%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2007-6545
  • Runcms » Runcms » Version: Any
    cpe:2.3:a:runcms:runcms:*


Contact Us

Shodan ® - All rights reserved