Lucene search

K
cve[email protected]CVE-2007-3061
HistoryJun 06, 2007 - 1:30 a.m.

CVE-2007-3061

2007-06-0601:30:00
CWE-255
web.nvd.nist.gov
23
cactushop
cve-2007-3061
information security
access control
vulnerability

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.022 Low

EPSS

Percentile

89.4%

Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb.

Affected configurations

NVD
Node
cactusoftcactushopRange6

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.022 Low

EPSS

Percentile

89.4%

Related for CVE-2007-3061