Vulnerabilities
Vulnerable Software
Acidcat:  >> Acidcat Cms  >> 3.4.1  Security Vulnerabilities
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.
CVSS Score
5.0
EPSS Score
0.033
Published
2010-03-16
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.
CVSS Score
7.5
EPSS Score
0.011
Published
2008-04-27
Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the field parameter.
CVSS Score
4.3
EPSS Score
0.06
Published
2008-04-27
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName, and To fields.
CVSS Score
7.5
EPSS Score
0.089
Published
2008-04-27
Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.
CVSS Score
7.5
EPSS Score
0.071
Published
2008-04-27


Contact Us

Shodan ® - All rights reserved