Vulnerability Details CVE-2008-5847
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.2%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2008-5847
-
cpe:2.3:a:constructr:constructr-cms:*
-
cpe:2.3:a:constructr:constructr-cms:3.00.0
-
cpe:2.3:a:constructr:constructr-cms:3.00.1
-
cpe:2.3:a:constructr:constructr-cms:3.00.2
-
cpe:2.3:a:constructr:constructr-cms:3.01.0
-
cpe:2.3:a:constructr:constructr-cms:3.01.1
-
cpe:2.3:a:constructr:constructr-cms:3.01.2
-
cpe:2.3:a:constructr:constructr-cms:3.01.3
-
cpe:2.3:a:constructr:constructr-cms:3.01.4
-
cpe:2.3:a:constructr:constructr-cms:3.01.5
-
cpe:2.3:a:constructr:constructr-cms:3.01.6
-
cpe:2.3:a:constructr:constructr-cms:3.01.7
-
cpe:2.3:a:constructr:constructr-cms:3.01.8
-
cpe:2.3:a:constructr:constructr-cms:3.01.9
-
cpe:2.3:a:constructr:constructr-cms:3.02.0
-
cpe:2.3:a:constructr:constructr-cms:3.02.1
-
cpe:2.3:a:constructr:constructr-cms:3.02.2
-
cpe:2.3:a:constructr:constructr-cms:3.02.3
-
cpe:2.3:a:constructr:constructr-cms:3.02.4