CVE-2006-0659
Runcms < 1.2 - Code Injection
Title source: ruleDescription
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php.
Exploits (1)
References (5)
Scores
EPSS
0.0582
EPSS Percentile
90.6%
Details
CWE
CWE-94
Status
published
Products (3)
runcms/runcms
1.1
runcms/runcms
1.1a
runcms/runcms
< 1.2
Published
Feb 13, 2006
Tracked Since
Feb 18, 2026