PT-2009-1634 · Cmme · Content Management Made Easy

Published

2009-02-18

·

Updated

2018-10-11

·

CVE-2008-6159

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Content Management Made Easy (CMME) version 1.19
Description The issue allows remote attackers to obtain system information by making a direct request to "info.php", which invokes the phpinfo function.
Recommendations For Content Management Made Easy (CMME) version 1.19, consider restricting access to the "info.php" file to prevent unauthorized disclosure of system information.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6159

Affected Products

Content Management Made Easy