First published: Tue Mar 14 2006(Updated: )
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.1a | |
Runcms Runcms | =1.3a | |
Runcms Runcms | =1.3a5 | |
Runcms Runcms | =1.2 | |
Runcms Runcms | =1.3a2 | |
Runcms Runcms | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1216 has a medium severity rating due to its potential to allow cross-site scripting attacks.
To fix CVE-2006-1216, sanitize user input in the id parameter of the bigshow.php script to prevent script injection.
CVE-2006-1216 affects Runcms versions 1.x, specifically 1.1 through 1.3a5.
CVE-2006-1216 is classified as a cross-site scripting (XSS) vulnerability.
Remote attackers can exploit CVE-2006-1216 by injecting arbitrary web scripts or HTML through the id parameter.