PT-2010-2699 · Acidcat · Acidcat Cms
Lionturk
·
Published
2010-03-16
·
Updated
2017-08-17
·
CVE-2010-0976
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Acidcat CMS version 3.5.x
Description
The issue allows remote attackers to access install.asp and other install *.asp scripts after the installation process has finished, potentially enabling them to restart the installation and have other unspecified impacts. This can be achieved via requests to install.asp and other related scripts.
Recommendations
For Acidcat CMS version 3.5.x, delete all files beginning with 'install' from the root directory after completing the installation, as instructed on the final installation screen.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acidcat Cms