CVE-2007-2538: SQL Injection
Published May 9, 2007
·Updated
SQL injection vulnerability in class/debug/debugshow.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executedqueries array parameter.
Affected Software
1 affected component
Runcms RunCMS<=1.5.2
Remediation
Patch Available
Patch Available
Event History
May 9, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2538?
CVE-2007-2538 has a high severity level due to the potential for remote code execution via SQL injection.
2
How do I fix CVE-2007-2538?
To fix CVE-2007-2538, update to a version of RunCms that is later than 1.5.2, which includes security patches.
3
What is the impact of CVE-2007-2538?
The impact of CVE-2007-2538 allows attackers to execute arbitrary SQL commands on the affected system, potentially compromising data integrity.
4
Which versions are affected by CVE-2007-2538?
All versions of RunCms 1.5.2 and earlier are affected by CVE-2007-2538.
5
Is CVE-2007-2538 a common vulnerability?
CVE-2007-2538 is known in the cybersecurity community but is specific to the RunCms content management system.