Description
|
|
A vulnerability has been identified in RunCms, which could be exploited by attackers to execute arbitrary SQL queries. This issue is caused by an input validation error in the "show_queries()" [class/debug/debug.php] function when processing the "executed_queries" parameter, which could be exploited by unauthenticated users to conduct SQL injection attacks.
Note : A second function (show_files) could also be exploited by unauthenticated attackers to verify the existence of certain files.
|