CVE-2006-0659

Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:runcms:runcms:1.1a:*:*:*:*:*:*:*
cpe:2.3:a:runcms:runcms:1.1:*:*:*:*:*:*:*
cpe:2.3:a:runcms:runcms:*:*:*:*:*:*:*:*

Information

Published : 2006-02-13 03:06

Updated : 2011-09-07 21:00


NVD link : CVE-2006-0659

Mitre link : CVE-2006-0659


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

runcms

  • runcms