Havalite CMS 'data/havalite.db3' File Database Information Disclosure
BID:56878
Info
Havalite CMS 'data/havalite.db3' File Database Information Disclosure
| Bugtraq ID: | 56878 |
| Class: | Design Error |
| CVE: |
CVE-2012-5892 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2012 12:00AM |
| Updated: | Dec 10 2012 12:00AM |
| Credit: | KedAns-Dz |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Havalite CMS 'data/havalite.db3' File Database Information Disclosure
Havalite CMS is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Havalite CMS is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
Havalite CMS 'data/havalite.db3' File Database Information Disclosure
Attackers can exploit this issue using a browser or readily available tools.
Attackers can exploit this issue using a browser or readily available tools.
Solution / Fix
Havalite CMS 'data/havalite.db3' File Database Information Disclosure
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Havalite CMS 'data/havalite.db3' File Database Information Disclosure
References:
References:
- Havalite CMS Homepage (Havalite)