Lucene search

K
prionPRIOn knowledge basePRION:CVE-2008-3924
HistorySep 04, 2008 - 6:41 p.m.

Improper access control

2008-09-0418:41:00
PRIOn knowledge base
www.prio-n.com
1

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.7%

The “Make a backup” functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.

CPENameOperatorVersion
cmmeeq1.12

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.7%

Related for PRION:CVE-2008-3924