CVE-2007-6546

RunCMS <1.6.1 - Info Disclosure

Title source: llm

Description

RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

Exploits (1)

exploitdb WRITEUP VERIFIED
by DSecRG · textwebappsphp
https://www.exploit-db.com/exploits/4790

Scores

EPSS 0.0652
EPSS Percentile 90.9%

Classification

Status draft

Affected Products (1)

runcms/runcms < 1.6

Timeline

Published Dec 28, 2007
Tracked Since Feb 18, 2026