CVE-2007-6546
RunCMS < 1.6 - Session Hijacking via Predictable Session ID
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6546. PoCs published by DSecRG.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in RunCMS 1.6, including SQL injection, XSS, PHP injection, and predictable session IDs. It provides specific endpoints and payloads for exploitation but does not include functional exploit code.
Description
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
Exploits (1)
This advisory details multiple vulnerabilities in RunCMS 1.6, including SQL injection, XSS, PHP injection, and predictable session IDs. It provides specific endpoints and payloads for exploitation but does not include functional exploit code.