7.5
CVSSv3

CVE-2018-12604

Published: 20/06/2018 Updated: 10/08/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

GreenCMS 2.3.0603 allows remote malicious users to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

njtech greencms 2.3.0603

Exploits

# Exploit Title: GreenCMS 230603 - remote obtain sensitive information # Date: 2018-06-21 # Exploit Author: vr_system # Vendor Homepage: githubcom/GreenCMS/GreenCMS/ # Software Link: githubcom/GreenCMS/GreenCMS/ # Version: GreenCMS 230603 # Tested on: windows 7 # CVE : CVE-2018-12604 # POC£ºsitecom/Data/Log/year_mo ...
GreenCMS version 230603 suffers from a sensitive information disclosure vulnerability ...