CVE-2008-7069 describes a critical information disclosure vulnerability in All Club CMS (ACCMS) version 0.0.2 and earlier. The system stores sensitive database configuration files, including credentials, under the web root with inadequate access controls, allowing unauthenticated remote attackers to directly access these files. This vulnerability carries a high CVSS score of 7.5, indicating a severe risk due to its network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or KEV listing, public exploit code exists on ExploitDB, and despite its age, the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.0.2CPE matchmatch criteria | cpe:2.3:a:paul_arbogast:accms:*:*:*:*:*:*:*:* | ||
0.0.1aCPE matchmatch criteria | cpe:2.3:a:paul_arbogast:accms:0.0.1a:*:*:*:*:*:*:* | ||
0.0.1cCPE matchmatch criteria | cpe:2.3:a:paul_arbogast:accms:0.0.1c:*:*:*:*:*:*:* | ||
0.0.1dCPE matchmatch criteria | cpe:2.3:a:paul_arbogast:accms:0.0.1d:*:*:*:*:*:*:* | ||
0.0.1eCPE matchmatch criteria | cpe:2.3:a:paul_arbogast:accms:0.0.1e:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.