CVE-2008-3924
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a…
Does this matter?
Lower severity and a low EPSS score (2.25%). Track it; it rarely justifies an emergency change on its own.
Description
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 2.25% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- hans oesterholt/cmme
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/31599Vendor Advisory
- http://securityreason.com/securityalert/4220
- http://www.securityfocus.com/bid/30854
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44684
- https://www.exploit-db.com/exploits/6313
- http://secunia.com/advisories/31599Vendor Advisory
- http://securityreason.com/securityalert/4220
- http://www.securityfocus.com/bid/30854
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44684
- https://www.exploit-db.com/exploits/6313
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.