Security Advisory

CVE-2009-1460

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-04-28 16:00:00
Last updated 2024-08-07 05:13:25
Assigner mitre
State PUBLISHED

Description

razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrators password hash and FTP user credentials; and (2) the root directory, (3) datastore/, and (4) admin/core/, which allows local users to have an unspecified impact.