7.5
CVSSv2

CVE-2008-7069

Published: 25/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

All Club CMS (ACCMS) 0.0.2 and previous versions stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain database configuration information, including credentials, via a direct request to accms.dat.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

paul arbogast accms 0.0.1c

paul arbogast accms 0.0.1a

paul arbogast accms

paul arbogast accms 0.0.1h

paul arbogast accms 0.0.1f

paul arbogast accms 0.0.1g

paul arbogast accms 0.0.1d

paul arbogast accms 0.0.1e

Exploits

#!/usr/bin/perl =about All Club CMS <= 002 Remote DB Config Retrieve Exploit ------------------------------------------------------- by athos - staker[at]hotmail[dot]it download on sourceforgenet ------------------------------------------------------- Usage: perl exploitpl localhost/cms [MODE] perl exploitpl localhos ...