CVE-2018-7251
AnchorCMS < 0.12.3a - Information Disclosure
Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (2)
NVD, NVD
CWE (1)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC (-)
Risk
CVSS Score
9.8 Critical
SSVC
-
KEV
-
EPSS
6.9%
Affected Products (-)
Vendors (1)
anchorcms
Products (1)
anchor
Versions (1)
0.12.3
Intel Resources (1)
Advisories (-)
-
Exploits (1)
PacketStorm
Plugins (-)
-
References (7)
General (5)
packetstormsecurity, andmp, github ...
Exploits & POcs (2)
packetstorm, exploit-db
Patches (-)
Advisories (-)
Summary
Descriptions
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
Se ha descubierto un problema en config/error.php en Anchor 0.12.3. El registro de errores se expone en un URI errors.log y contiene credenciales de MySQL si ha ocurrido un error de MySQL (como "Too many connections").
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-02-19 CVE Reserved
- 2018-02-19 CVE Published
- 2019-10-03 First Exploit
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Threat Intelligence Resources (1)
Select | Title | Date |
---|
Security Advisory details:
Select an advisory to view details here.
Select | Title | Date |
---|---|---|
Anchor CMS 0.12.3a Information Disclosure | 2019-10-03 |
Select an exploit to view details here.
References (7)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/154723/Anchor-CMS-0.12.3a-Information-Disclosure.html | X_refsource_misc |
|
http://www.andmp.com/2018/02/advisory-assigned-CVE-2018-7251-in-anchorcms.html | Third Party Advisory | |
https://github.com/anchorcms/anchor-cms/issues/1247 | Issue Tracking | |
https://github.com/anchorcms/anchor-cms/releases/tag/0.12.7 | X_refsource_confirm | |
https://twitter.com/finnwea/status/965279233030393856 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/154723 | 2019-10-03 | |
https://www.exploit-db.com/exploits/47459 | 2019-10-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|