First published: Wed Aug 24 2005(Updated: )
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2) subquery parameters to the newbb plus module, the forum parameter to (3) newtopic.php, (4) edit.php, or (5) reply.php in the newbb plus module, or (6) the msg_id parameter to print.php in the messages module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.1a | |
Runcms Runcms | =1.2 | |
Runcms Runcms | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2692 is considered to have a high severity due to its potential for remote SQL injection, allowing attackers to execute arbitrary SQL commands.
To fix CVE-2005-2692, upgrade to a version of RunCMS that is not vulnerable, specifically versions earlier than 1.2.
CVE-2005-2692 affects RunCMS versions 1.1 and 1.2.
The attack vectors for CVE-2005-2692 include vulnerabilities in the newbb plus module using parameters like addquery, subquery, forum, and more.
Yes, a remote attacker can exploit CVE-2005-2692 without authentication, leading to potential unauthorized access to the database.