CVE-2012-5892
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which a
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.
MEDIUM · CVSS 5
EPSS 0.0026
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0