Unrated severityNVD Advisory· Published Dec 28, 2007· Updated Apr 23, 2026
CVE-2007-6545
CVE-2007-6545
Description
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.securityfocus.com/bid/27019nvdExploitPatch
- osvdb.org/41241nvd
- osvdb.org/41242nvd
- osvdb.org/41243nvd
- securityreason.com/securityalert/3493nvd
- www.dsec.ru/about/articles/web_xssnvd
- www.runcms.org/modules/mydownloads/singlefile.phpnvd
- www.securityfocus.com/archive/1/485512/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39292nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39293nvd
- www.exploit-db.com/exploits/4790nvd
News mentions
0No linked articles in our index yet.