CVE-2007-2539
RunCms < 1.5.2 - Information Disclosure via show_files Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2539. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in RunCms <= 1.5.2 via the debug_show.php file, allowing unauthenticated credential disclosure. It uses a blind SQL injection technique to extract the admin username and password hash.
Description
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors.
Exploits (1)
This exploit targets a SQL injection vulnerability in RunCms <= 1.5.2 via the debug_show.php file, allowing unauthenticated credential disclosure. It uses a blind SQL injection technique to extract the admin username and password hash.