PT-2009-1330 · Chilek · Chilek Content Management System

Publicado

2009-01-06

·

Atualizado

2018-10-11

·

CVE-2008-5853

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chilek Content Management System (aka ChiCoMaS) versions 2.0.4 and earlier
Description The issue allows remote attackers to obtain sensitive information due to insufficient access control. This can be achieved by making a direct request for config.inc to obtain database credentials or by requesting a backup/ URI to read database backups.
Recommendations For Chilek Content Management System (aka ChiCoMaS) versions 2.0.4 and earlier, consider restricting access to sensitive files such as config.inc and database backups in the backup/ URI to minimize the risk of exploitation. As a temporary workaround, limit access to these files until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5853

Produtos afetados

Chilek Content Management System