RunCms Multiple SQL Injection Vulnerabilities
BID:19913
CVE-2006-4667 |Info
RunCms Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 19913 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Sep 08 2006 09:07PM |
| Credit: | Omid is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
RunCMS RunCMS 1.4.1 RunCMS RunCMS 1.2 RunCMS RunCMS 1.1 A RunCMS RunCMS 1.1 RunCMS RunCMS 1.3.a5 RunCMS RunCMS 1.3.a2 RunCMS RunCMS 1.3.a |
| Not Vulnerable: |
RunCMS RunCMS 1.4.1 fixpack b |
Discussion
RunCms Multiple SQL Injection Vulnerabilities
RunCms is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Version 1.4.1 and earlier are vulnerable; other versions may also be affected.
RunCms is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Version 1.4.1 and earlier are vulnerable; other versions may also be affected.
Exploit / POC
RunCms Multiple SQL Injection Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
RunCms Multiple SQL Injection Vulnerabilities
Solution:
The vendor released a patch version 1.4.1 fixpack b to address this issue. Please see the references for more information.
Solution:
The vendor released a patch version 1.4.1 fixpack b to address this issue. Please see the references for more information.