includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-08-24T04:00:00Z

Updated: 2024-09-17T04:04:31.147Z

Reserved: 2005-08-24T00:00:00Z

Link: CVE-2005-2691

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-08-24T04:00:00.000

Modified: 2008-09-05T20:52:26.470

Link: CVE-2005-2691

cve-icon Redhat

No data.