Description
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Pedro Andujar · textwebappsphp
https://www.exploit-db.com/exploits/38740
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
http://www.digitalsec.net/stuff/explt+advs/CM3.AcoraCMS.v6.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/96666
Scores
EPSS
0.1172
EPSS Percentile
93.7%
Details
CWE
CWE-200
Status
published
Products (4)
ddsn/cm3_acora_content_management_system
5.5.0\/1b-p1
ddsn/cm3_acora_content_management_system
5.5.7\/12b
ddsn/cm3_acora_content_management_system
6.0.2\/1a
ddsn/cm3_acora_content_management_system
6.0.6\/1a
Published
Jun 06, 2014
Tracked Since
Feb 18, 2026