CVE-2012-5892 Information
Feb 14, 2021
cve
Description
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.
Reference
http://osvdb.org/80770 http://packetstormsecurity.org/files/111358/Havalite-CMS-Shell-Upload-SQL-Injection-Disclosure.html https://exchange.xforce.ibmcloud.com/vulnerabilities/74488
Share on: