5
CVSSv2

CVE-2009-3802

Published: 27/10/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Amiro.CMS 5.4.0.0 and previous versions allows remote malicious users to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

amirocms amiro.cms 5.0.7

amirocms amiro.cms 4.2.5

amirocms amiro.cms

amirocms amiro.cms 5.2.3

amirocms amiro.cms 4.2.2.0

amirocms amiro.cms 4.2.1.0

amirocms amiro.cms 5.2.2

amirocms amiro.cms 5.2

amirocms amiro.cms 4.2.0.5

amirocms amiro.cms 4.0.8.0

amirocms amiro.cms 4.2.4

amirocms amiro.cms 4.2.3.0

Exploits

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ [ONSEC-09-005] AmiroCMS root folder disclosure Objective: Amiro CMS <= 5400 Type: Disclosure of ways Threat: Medium Date Discovered: 01072009 Date of notification Developer: 01072009 Released fixes: 06102009 Author: Vladim ...