CVE-2007-6547

RunCMS <1.6.1 - Info Disclosure

Title source: llm

Description

RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

Exploits (1)

exploitdb WRITEUP VERIFIED
by DSecRG · textwebappsphp
https://www.exploit-db.com/exploits/4790

Scores

EPSS 0.0601
EPSS Percentile 90.5%

Classification

Status draft

Affected Products (1)

runcms/runcms < 1.6

Timeline

Published Dec 28, 2007
Tracked Since Feb 18, 2026