PT-2009-1330 · Chilek · Chilek Content Management System
Published
2009-01-06
·
Updated
2018-10-11
·
CVE-2008-5853
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Chilek Content Management System (aka ChiCoMaS) versions 2.0.4 and earlier
Description
The issue allows remote attackers to obtain sensitive information due to insufficient access control. This can be achieved by making a direct request for
config.inc to obtain database credentials or by requesting a backup/ URI to read database backups.Recommendations
For Chilek Content Management System (aka ChiCoMaS) versions 2.0.4 and earlier, consider restricting access to sensitive files such as
config.inc and database backups in the backup/ URI to minimize the risk of exploitation. As a temporary workaround, limit access to these files until a proper fix is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chilek Content Management System