CVE-2009-3813
RunCMS 2M1 - Authenticated SQL Injection via Forum Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://retrogod.altervista.org/9sg_runcms_forum_sql.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37137
Scores
EPSS
0.0090
EPSS Percentile
55.9%
Details
CWE
CWE-89
Status
published
Products (1)
runcms/runcms
2m1
Published
Oct 27, 2009
Tracked Since
Feb 18, 2026