WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/wabcmsn.mdb. NOTE: this issue was originally reported for "webCMS," but this was an error by an unreliable researcher.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.attrition.org/pipermail/vim/2007-May/001637.html | mailing list |
http://secunia.com/advisories/25453 | third party advisory vendor advisory |
http://www.xmors-security.com/advisory/webCMS_1.00.txt | |
http://www.securityfocus.com/archive/1/469618/100/0/threaded | mailing list |
http://osvdb.org/36698 | vdb entry |