CVE-2007-6547
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.
Date published : 2007-12-27
http://www.securityfocus.com/bid/27019
http://www.securityfocus.com/archive/1/485512/100/0/threaded