CVE-2009-2022 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 5.2% (pctl 92)
Patch early
A public exploit exists.
Description
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 5.16% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| fipsasp | fipscms light |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure | 2009-06-08 |
References
→ the Explorer · watch your stack · NVD