Unspecified vulnerability in newbbplus in RunCms 1.5.2 has unknown impact and attack vectors.
SQL injection vulnerability in class/debug/debugshow.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executedqueries array parameter.
The showfiles function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors.