includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.
Link | Tags |
---|---|
http://secunia.com/advisories/16514 | third party advisory vendor advisory |
http://www.gulftech.org/?node=research&article_id=00094-08192005 | vendor advisory |