includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:22:47

Updated: 2022-10-03T16:22:47

Reserved: 2022-10-03T00:00:00


Link: CVE-2005-2691

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2005-08-24T04:00:00.000

Modified: 2008-09-05T20:52:26.470


Link: CVE-2005-2691

JSON object: View

cve-icon Redhat Information

No data.