4.3
CVE-2008-3924
- EPSS 2.25%
- Veröffentlicht 04.09.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hans Oesterholt ≫ Cmme Version1.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.25% | 0.806 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://secunia.com/advisories/31599
http://securityreason.com/securityalert/4220
http://www.securityfocus.com/bid/30854
https://www.exploit-db.com/exploits/6313
https://exchange.xforce.ibmcloud.com/vulnerabilities/44684