First published: Tue Oct 27 2009(Updated: )
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =2m1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3813 is considered a medium severity vulnerability due to the potential for authenticated users to execute arbitrary SQL commands.
CVE-2009-3813 affects users of RunCMS version 2M1.
To fix CVE-2009-3813, it is recommended to update to the latest version of RunCMS that addresses these SQL injection vulnerabilities.
CVE-2009-3813 can be exploited through the forum parameter in modules/forum/post.php and the forum_id variable in modules/forum/class/class.permissions.php.
CVE-2009-3813 is classified as an SQL injection vulnerability.