CVE-2007-6544

RunCMS <1.6.1 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.

Exploits (3)

exploitdb WRITEUP VERIFIED
by DSecRG · textwebappsphp
https://www.exploit-db.com/exploits/4790
exploitdb WORKING POC VERIFIED
by sh2kerr · perlwebappsphp
https://www.exploit-db.com/exploits/4792
exploitdb WORKING POC VERIFIED
by sh2kerr · perlwebappsphp
https://www.exploit-db.com/exploits/4787

Scores

EPSS 0.0296
EPSS Percentile 86.3%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

runcms/runcms

Timeline

Published Dec 28, 2007
Tracked Since Feb 18, 2026