Lucene search

K
cveMitreCVE-2005-2691
HistoryAug 24, 2005 - 4:00 a.m.

CVE-2005-2691

2005-08-2404:00:00
mitre
web.nvd.nist.gov
29
cve
runcms
security vulnerability
arbitrary code execution
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.014

Percentile

86.5%

includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.

Affected configurations

Nvd
Node
runcmsruncmsMatch1.1
OR
runcmsruncmsMatch1.1a
OR
runcmsruncmsMatch1.2
VendorProductVersionCPE
runcmsruncms1.1cpe:2.3:a:runcms:runcms:1.1:*:*:*:*:*:*:*
runcmsruncms1.1acpe:2.3:a:runcms:runcms:1.1a:*:*:*:*:*:*:*
runcmsruncms1.2cpe:2.3:a:runcms:runcms:1.2:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.014

Percentile

86.5%