Total vulnerabilities in the database
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.
Software | From | Fixed in |
---|---|---|
acidcat / acidcat_cms | 3.3.5 | 3.3.5.x |
acidcat / acidcat_cms | 2.1.12 | 2.1.12.x |
acidcat / acidcat_cms | 3.5.0 | 3.5.0.x |
acidcat / acidcat_cms | 3.4.2 | 3.4.2.x |
acidcat / acidcat_cms | 3.4.0 | 3.4.0.x |
acidcat / acidcat_cms | 2.1.11 | 2.1.11.x |
acidcat / acidcat_cms | - | 3.5.3.x |
acidcat / acidcat_cms | 3.5.2 | 3.5.2.x |
acidcat / acidcat_cms | 3.4.1 | 3.4.1.x |
acidcat / acidcat_cms | 3.5.1 | 3.5.1.x |
acidcat / acidcat_cms | 2.1.13 | 2.1.13.x |