First published: Fri Dec 28 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | <=1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6545 is classified as a high severity vulnerability due to its potential impact on user security and privacy.
To fix CVE-2007-6545, it's recommended to upgrade to RunCMS version 1.6.1 or later which addresses these XSS vulnerabilities.
The attack vectors for CVE-2007-6545 include manipulating the subject parameter in modules/news/submit.php and the PATH_INFO in modules/news/index.php.
CVE-2007-6545 exploits multiple cross-site scripting (XSS) vulnerabilities that allow attackers to inject arbitrary scripts through various parameters.
Users of RunCMS versions prior to 1.6.1 are affected by CVE-2007-6545, making their applications vulnerable to XSS attacks.