Lucene search

K
cve[email protected]CVE-2008-5847
HistoryJan 05, 2009 - 8:30 p.m.

CVE-2008-5847

2009-01-0520:30:02
CWE-255
web.nvd.nist.gov
22
cve-2008-5847
constructr cms
password storage
mysql
database security
sensitive information

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.1%

Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.

Affected configurations

NVD
Node
constructrconstructr-cmsRange3.02.5
OR
constructrconstructr-cmsMatch3.00.0alpha
OR
constructrconstructr-cmsMatch3.00.1alpha
OR
constructrconstructr-cmsMatch3.00.2alpha
OR
constructrconstructr-cmsMatch3.01.0beta
OR
constructrconstructr-cmsMatch3.01.1beta
OR
constructrconstructr-cmsMatch3.01.2beta
OR
constructrconstructr-cmsMatch3.01.3beta
OR
constructrconstructr-cmsMatch3.01.4beta
OR
constructrconstructr-cmsMatch3.01.5beta
OR
constructrconstructr-cmsMatch3.01.6beta
OR
constructrconstructr-cmsMatch3.01.7beta
OR
constructrconstructr-cmsMatch3.01.8beta
OR
constructrconstructr-cmsMatch3.01.9beta
OR
constructrconstructr-cmsMatch3.02.0
OR
constructrconstructr-cmsMatch3.02.1
OR
constructrconstructr-cmsMatch3.02.2
OR
constructrconstructr-cmsMatch3.02.3
OR
constructrconstructr-cmsMatch3.02.4

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.1%

Related for CVE-2008-5847