PT-2009-1330 · Chilek · Chilek Content Management System

Published

2009-01-06

·

Updated

2018-10-11

·

CVE-2008-5853

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chilek Content Management System (aka ChiCoMaS) versions 2.0.4 and earlier
Description The issue allows remote attackers to obtain sensitive information due to insufficient access control. This can be achieved by making a direct request for config.inc to obtain database credentials or by requesting a backup/ URI to read database backups.
Recommendations For Chilek Content Management System (aka ChiCoMaS) versions 2.0.4 and earlier, consider restricting access to sensitive files such as config.inc and database backups in the backup/ URI to minimize the risk of exploitation. As a temporary workaround, limit access to these files until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5853

Affected Products

Chilek Content Management System