PT-2010-2787 · Ar · Ar Web Content Manager
Alnjm33
·
Published
2010-03-23
·
Updated
2017-08-17
·
CVE-2010-1066
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AR Web Content Manager (AWCM) version 2.1
Description
The issue allows remote attackers to download a database due to insufficient access control of sensitive information stored under the web root. This can be achieved by making a direct request for the
control/db backup.php endpoint.Recommendations
For AR Web Content Manager (AWCM) version 2.1, restrict access to the
control/db backup.php endpoint to minimize the risk of exploitation. Consider implementing proper access controls for sensitive information stored under the web root.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ar Web Content Manager