4.3
CVSSv2

CVE-2008-3924

Published: 04/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hans oesterholt cmme 1.12

Exploits

################################################################################################################## [+] CMME 112 (LFI/XSS/CSRF/Download Backup/MkDir) Multiple Remote Vulnerabilities [+] Discovered By SirGod [+] wwwmortal-teamorg [+] Greetz : EMINEM,Ras,Puscas_marin,ToxicBlood,M ...