← Back

CVE-2008-5847

nvd nist
Published: Jan 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.

Affected (19)

1 product
Constructr Cms
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Constructr
Up to 3.02.5
Version 3.00.0 alpha
Version 3.00.1 alpha
Version 3.00.2 alpha
Version 3.01.0 beta
Version 3.01.1 beta
Version 3.01.2 beta
Version 3.01.3 beta
Version 3.01.4 beta
Version 3.01.5 beta
Version 3.01.6 beta
Version 3.01.7 beta
Version 3.01.8 beta
Version 3.01.9 beta
Version 3.02.0
Version 3.02.1
Version 3.02.2
Version 3.02.3
Version 3.02.4

Related CWEs

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.