VulnerabilityModified
CVE-2010-1066
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.
MEDIUM 5.0EPSS 2.46%
Does this matter?
Lower severity and a low EPSS score (2.46%). Track it; it rarely justifies an emergency change on its own.
Description
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.46% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- the-ghost/ar web content manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1001-exploits/awcm-backup.txtExploit
- http://secunia.com/advisories/38065Vendor Advisory
- http://www.exploit-db.com/exploits/11025Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55445
- http://packetstormsecurity.org/1001-exploits/awcm-backup.txtExploit
- http://secunia.com/advisories/38065Vendor Advisory
- http://www.exploit-db.com/exploits/11025Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55445
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.