CVE-2010-0984

Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:P/I:N/A:N
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
acidcatacidcat_cms
𝑥
≤ 3.5.3
acidcatacidcat_cms
2.1.11
acidcatacidcat_cms
2.1.12
acidcatacidcat_cms
2.1.13
acidcatacidcat_cms
3.3.5
acidcatacidcat_cms
3.4.0
acidcatacidcat_cms
3.4.1
acidcatacidcat_cms
3.4.2
acidcatacidcat_cms
3.5.0
acidcatacidcat_cms
3.5.1
acidcatacidcat_cms
3.5.2
𝑥
= Vulnerable software versions
Common Weakness Enumeration