Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6547. PoCs published by DSecRG.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in RunCMS 1.6, including SQL injection, XSS, PHP injection, and predictable session IDs. It provides specific endpoints and payloads for exploitation but does not include functional exploit code.
Description
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.
Exploits (1)
This advisory details multiple vulnerabilities in RunCMS 1.6, including SQL injection, XSS, PHP injection, and predictable session IDs. It provides specific endpoints and payloads for exploitation but does not include functional exploit code.