Total vulnerabilities in the database
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.
Software | From | Fixed in |
---|---|---|
runcms / runcms | 2m1 | 2m1.x |