First published: Fri Feb 24 2006(Updated: )
Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.1a | |
Runcms Runcms | =1.3a | |
Runcms Runcms | =1.3a5 | |
Runcms Runcms | =1.2 | |
Runcms Runcms | =1.3a2 | |
Runcms Runcms | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0875 is classified as a moderate severity vulnerability.
To fix CVE-2006-0875, sanitize the lid parameter input in ratefile.php to prevent cross-site scripting attacks.
CVE-2006-0875 affects RunCMS versions 1.1, 1.1a, 1.2, 1.3a, and 1.3a5.
CVE-2006-0875 allows remote attackers to execute arbitrary web scripts or HTML via cross-site scripting.
Yes, CVE-2006-0875 remains a risk for users of the affected RunCMS versions that have not been patched.