CVE-2007-6546
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
Date published : 2007-12-27
http://www.securityfocus.com/bid/27019
http://www.securityfocus.com/archive/1/485512/100/0/threaded