First published: Tue Nov 22 2005(Updated: )
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponent Exponent | =0.94 | |
Exponent Exponent | =0.96.3 | |
Exponent Exponent | =0.96.1 | |
Exponent Exponent | =0.95 | |
Exponent Exponent | =0.96.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3766 has a medium severity rating due to the exposure of sensitive user pages.
To fix CVE-2005-3766, ensure that sensitive files are stored outside the web document root and implement proper access controls.
CVE-2005-3766 affects Exponent CMS versions 0.94, 0.95, 0.96.1, 0.96.3, and 0.96.4.
Attackers can exploit CVE-2005-3766 to view sensitive user data by directly accessing exposed pages.
A workaround for CVE-2005-3766 includes modifying the server configuration to restrict access to sensitive directories.