CVE-2006-0875: Medium severity Runcms RunCMS vulnerability
Published Feb 24, 2006
·Updated
Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.
Affected Software
6 affected components
Runcms RunCMS=1.1a
Runcms RunCMS=1.3a
Runcms RunCMS=1.3a5
Runcms RunCMS=1.2
Runcms RunCMS=1.3a2
Runcms RunCMS=1.1
Event History
Feb 24, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0875?
CVE-2006-0875 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2006-0875?
To fix CVE-2006-0875, sanitize the lid parameter input in ratefile.php to prevent cross-site scripting attacks.
3
Which versions of RunCMS are affected by CVE-2006-0875?
CVE-2006-0875 affects RunCMS versions 1.1, 1.1a, 1.2, 1.3a, and 1.3a5.
4
What type of attack does CVE-2006-0875 allow?
CVE-2006-0875 allows remote attackers to execute arbitrary web scripts or HTML via cross-site scripting.
5
Is CVE-2006-0875 still a risk for users?
Yes, CVE-2006-0875 remains a risk for users of the affected RunCMS versions that have not been patched.