Vulnerabilities > CVE-2006-0875 - Cross-Site Scripting vulnerability in RunCMS

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
runcms
exploit available

Summary

Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.

Exploit-Db

descriptionRunCMS 1.x Ratefile.PHP Cross-Site Scripting Vulnerability. CVE-2006-0875. Webapps exploit for php platform
idEDB-ID:27256
last seen2016-02-03
modified2006-02-22
published2006-02-22
reporterRoozbeh Afrasiabi
sourcehttps://www.exploit-db.com/download/27256/
titleRunCMS 1.x Ratefile.PHP Cross-Site Scripting Vulnerability