First published: Tue Oct 27 2009(Updated: )
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =2m1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3814 is classified as a high severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2009-3814, you should update RunCMS to a version where this vulnerability is patched.
CVE-2009-3814 affects remote authenticated administrators using RunCMS version 2M1.
CVE-2009-3814 can be exploited to execute arbitrary PHP code through the Filter/Banning feature.
The cause of CVE-2009-3814 is a static code injection vulnerability in the RunCMS application.