CVE-2008-7069 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.53% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-08-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| paul arbogast | accms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | All Club CMS 0.0.2 - Remote Database Configuration Retrieve | 2008-11-28 |
References
→ the Explorer · watch your stack · NVD