CVE-2014-8702 Information
Feb 14, 2021
cve
Description
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password which reveals the installation path in an error message.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://rossmarks.uk/portfolio.php http://rossmarks.uk/whitepapers/wonder_cms_2014.txt http://www.securityfocus.com/bid/97192
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: