Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kabus

#35254of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2007-1576
7.5
2007-01-05
Newscmslite · Newscmslite · CVE-2007-0091
**Name of the Vulnerable Software and Affected Versions** newsCMSlite (affected versions not specified) **Description** The issue allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb, due to insufficient access control of sensitive information stored under the web root. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.