Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

RunCMS < 1.5.2 Build 20070504 SQL Injection

Medium

Synopsis

The remote host is vulnerable to a SQL Injection attack.

Description

The remote host is running RunCMS, a web-based content management and messaging system. This version of RunCMS is vulnerable to a remote SQL injection flaw. Flaws within the SQL-handling routines of the 'debug_show.php' script are the root cause of this vulnerability. An attacker exploiting this flaw would only need to be able to send specially crafted queries to the 'debug_show.php' script. Successful exploitation would result in the attacker being able to execute arbitrary SQL commands on the remote database server.

Solution

Upgrade to version 1.5.2 Build 20070504 or higher.