Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2010-0984

Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.
0
Attacker Value
Unknown

CVE-2005-4371

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a request to databases/acidcat.mdb.
0
Attacker Value
Unknown

CVE-2005-4370

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
SQL injection vulnerability in main_content.asp in Acidcat 2.1.13 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter to default.asp.
0