CVE-2007-6545: XSS
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATHINFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6545?
CVE-2007-6545 is classified as a high severity vulnerability due to its potential impact on user security and privacy.
How do I fix CVE-2007-6545?
To fix CVE-2007-6545, it's recommended to upgrade to RunCMS version 1.6.1 or later which addresses these XSS vulnerabilities.
What are the attack vectors for CVE-2007-6545?
The attack vectors for CVE-2007-6545 include manipulating the subject parameter in modules/news/submit.php and the PATH_INFO in modules/news/index.php.
What kind of vulnerabilities does CVE-2007-6545 exploit?
CVE-2007-6545 exploits multiple cross-site scripting (XSS) vulnerabilities that allow attackers to inject arbitrary scripts through various parameters.
Who is affected by CVE-2007-6545?
Users of RunCMS versions prior to 1.6.1 are affected by CVE-2007-6545, making their applications vulnerable to XSS attacks.