peter bassill · operator
$ cve CVE-2007-3556 JSON

CVE-2007-3556 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.02% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2007-07-04
Last modified2026-06-16

Affected (1)

VendorProduct
doubleflexliesbeth base cms

Public exploits

SourceTitleDate
exploit-dbLiesbeth Base CMS - Information Disclosure2007-07-02

References

→ the Explorer  ·  watch your stack  ·  NVD