Vulnerabilities > CVE-2007-0091 - Unspecified vulnerability in Katy Whitton web Development Newscmslite
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN katy-whitton-web-development
exploit available
Summary
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | newsCMSlite (newsCMS.mdb) Remote Password Disclosure Vulnerability. CVE-2007-0091. Webapps exploit for asp platform |
file | exploits/asp/webapps/3066.txt |
id | EDB-ID:3066 |
last seen | 2016-01-31 |
modified | 2007-01-01 |
platform | asp |
port | |
published | 2007-01-01 |
reporter | KaBuS |
source | https://www.exploit-db.com/download/3066/ |
title | newsCMSlite newsCMS.mdb Remote Password Disclosure Vulnerability |
type | webapps |