Vulnerabilities > CVE-2007-6546 - Input Validation vulnerability in RunCMS

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
runcms
exploit available

Summary

RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

Vulnerable Configurations

Part Description Count
Application
Runcms
1

Exploit-Db

descriptionRunCMS 1.6 Multiple Remote Vulnerabilities. CVE-2007-6545,CVE-2007-6546,CVE-2007-6547,CVE-2007-6548. Webapps exploit for php platform
fileexploits/php/webapps/4790.txt
idEDB-ID:4790
last seen2016-01-31
modified2007-12-25
platformphp
port
published2007-12-25
reporterDSecRG
sourcehttps://www.exploit-db.com/download/4790/
titleruncms 1.6 - Multiple Vulnerabilities
typewebapps