VulnerabilityModified
CVE-2009-3597
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.
MEDIUM 5.0EPSS 3.21%
Does this matter?
Lower severity and a low EPSS score (3.21%). Track it; it rarely justifies an emergency change on its own.
Description
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.21% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552
- Affected
- digitaldesign cms project/digitaldesign cms
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/9115Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51676Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9115Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51676Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.