vendor:
newsCMSlite
by:
KabusTR.coM
3.3
CVSS
LOW
Remote Database Download
CWE
Product Name: newsCMSlite
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
newsCMSlite Remote Password Disclosure Vulnerability
The vulnerability allows an attacker to remotely download the newsCMS.mdb database file, which contains sensitive information such as passwords.
Mitigation:
The vendor should implement proper access controls and secure the database to prevent unauthorized access.