CVE-2012-5892
EUVD-2012-576617.11.2012, 21:55
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| havalite | cms | 𝑥 ≤ 1.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References