CVE-2007-3556

Liesbeth base CMS - Info Disclosure

Title source: llm
STIX 2.1

Description

Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.

Exploits (1)

exploitdb WRITEUP VERIFIED
by durito · textwebappsphp
https://www.exploit-db.com/exploits/30262

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35243
Various Sources x_refsource_misc
http://securityvulns.ru/Rdocument392.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/45744
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/472727/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2857
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24749

Scores

EPSS 0.0794
EPSS Percentile 92.1%

Details

Status published
Products (1)
doubleflex/liesbeth_base_cms
Published Jul 04, 2007
Tracked Since Feb 18, 2026