CVE-2012-5892

Publication date

2012-11-17 21:00:00

Family

mitre

State

PUBLISHED

Description

Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.