First published: Tue Jun 09 2009(Updated: )
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2022 has a high severity rating due to its ability to expose sensitive information without proper access controls.
To fix CVE-2009-2022, ensure that sensitive files are stored outside of the web root and implement proper access controls.
CVE-2009-2022 exposes a database file that may contain sensitive user information and credentials.
CVE-2009-2022 specifically affects fipsCMS Light version 2.1.
Yes, remote attackers can easily exploit CVE-2009-2022 by directly requesting the vulnerable database file.