Vulnerability Description
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Runcms | Runcms | <= 1.2 |
References
- http://retrogod.altervista.org/runcms_13a_xpl.htmlExploit
- http://www.securityfocus.com/archive/1/424708ExploitVendor Advisory
- http://www.securityfocus.com/bid/16578
- http://retrogod.altervista.org/runcms_13a_xpl.htmlExploit
- http://www.securityfocus.com/archive/1/424708ExploitVendor Advisory
- http://www.securityfocus.com/bid/16578
FAQ
What is CVE-2006-1793?
CVE-2006-1793 is a vulnerability with a CVSS score of 7.6 (HIGH). Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NO...
How severe is CVE-2006-1793?
CVE-2006-1793 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1793?
Check the references section above for vendor advisories and patch information. Affected products include: Runcms Runcms.