CVE-2007-6544
RunCMS <1.6.1 - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.
Exploits (3)
References (13)
Scores
EPSS
0.0296
EPSS Percentile
86.3%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
runcms/runcms
Timeline
Published
Dec 28, 2007
Tracked Since
Feb 18, 2026