CVE-2006-1216: XSS
Published Mar 14, 2006
·Updated
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Affected Software
6 affected components
Runcms RunCMS=1.1a
Runcms RunCMS=1.3a
Runcms RunCMS=1.3a5
Runcms RunCMS=1.2
Runcms RunCMS=1.3a2
Runcms RunCMS=1.1
Remediation
Patch Available
Event History
Mar 14, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1216?
CVE-2006-1216 has a medium severity rating due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2006-1216?
To fix CVE-2006-1216, sanitize user input in the id parameter of the bigshow.php script to prevent script injection.
3
Which versions of Runcms are affected by CVE-2006-1216?
CVE-2006-1216 affects Runcms versions 1.x, specifically 1.1 through 1.3a5.
4
What type of vulnerability is CVE-2006-1216?
CVE-2006-1216 is classified as a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2006-1216?
Remote attackers can exploit CVE-2006-1216 by injecting arbitrary web scripts or HTML through the id parameter.