Lucene search

K
cve[email protected]CVE-2008-3924
HistorySep 04, 2008 - 6:41 p.m.

CVE-2008-3924

2008-09-0418:41:00
CWE-264
web.nvd.nist.gov
24
cve-2008-3924
content management made easy
cmme 1.12
cmme 1.19
access control
remote attackers
password hashes

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.7%

The “Make a backup” functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.

Affected configurations

NVD
Node
hans_oesterholtcmmeMatch1.12

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.7%

Related for CVE-2008-3924