################################################################### RunCMS 1.6.1 Multiple XSS and XSRF Vulnerabilties by NBBN ################################################################### [b] 1) Create Webmaster (admin) XSRF Vulnerability[/b]
Also with XSRF an attacker can update the profile of all users. He can change the password etc... [b]2) Cross-Site Scripting (an attacker can only attack an admin)[/b]