The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-09-04T18:00:00
Updated: 2024-08-07T10:00:42.060Z
Reserved: 2008-09-04T00:00:00
Link: CVE-2008-3924
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-09-04T18:41:00.000
Modified: 2024-11-21T00:50:29.373
Link: CVE-2008-3924
Redhat
No data.