CVE-2007-6545
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.
- Affected products
- Runcms
- Runcms
- ≤ 1.6
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 4.1% (90th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2007-12-28
CVE-2007-6545 at NVD
1 known exploit for CVE-2007-6545
Proof-of-concept code and exploit modules indexed by Sploitus