CVE-2009-3597
08.10.2009, 17:30
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.Enginsight
Vendor | Product | Version |
---|---|---|
digitaldesign_cms_project | digitaldesign_cms | 0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration