CVE-2008-5847
05.01.2009, 20:30
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.Enginsight
Vendor | Product | Version |
---|---|---|
constructr | constructr-cms | 𝑥 ≤ 3.02.5 |
constructr | constructr-cms | 3.00.0:alpha |
constructr | constructr-cms | 3.00.1:alpha |
constructr | constructr-cms | 3.00.2:alpha |
constructr | constructr-cms | 3.01.0:beta |
constructr | constructr-cms | 3.01.1:beta |
constructr | constructr-cms | 3.01.2:beta |
constructr | constructr-cms | 3.01.3:beta |
constructr | constructr-cms | 3.01.4:beta |
constructr | constructr-cms | 3.01.5:beta |
constructr | constructr-cms | 3.01.6:beta |
constructr | constructr-cms | 3.01.7:beta |
constructr | constructr-cms | 3.01.8:beta |
constructr | constructr-cms | 3.01.9:beta |
constructr | constructr-cms | 3.02.0 |
constructr | constructr-cms | 3.02.1 |
constructr | constructr-cms | 3.02.2 |
constructr | constructr-cms | 3.02.3 |
constructr | constructr-cms | 3.02.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration