Vulnerabilities > CVE-2008-5847 - Credentials Management vulnerability in Constructr Constructr-Cms

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
high complexity
constructr
CWE-255
exploit available

Summary

Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionConstructr CMS <= 3.02.5 Stable Multiple Remote Vulnerabilities. CVE-2008-5847,CVE-2008-5859,CVE-2008-5860. Webapps exploit for php platform
fileexploits/php/webapps/7529.txt
idEDB-ID:7529
last seen2016-02-01
modified2008-12-19
platformphp
port
published2008-12-19
reporterfuzion
sourcehttps://www.exploit-db.com/download/7529/
titleconstructr CMS <= 3.02.5 stable Multiple Vulnerabilities
typewebapps