CVE-2010-0976
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
16/03/2010
Last modified:
11/04/2025
Description
Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts. NOTE: the final installation screen states "Important: you must now delete all files beginning with 'install' from the root directory."
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:acidcat:acidcat_cms:3.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:acidcat:acidcat_cms:3.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:acidcat:acidcat_cms:3.5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:acidcat:acidcat_cms:3.5.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.org/1001-exploits/acidcatcms-disclose.txt
- http://www.exploit-db.com/exploits/10972
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55331
- http://packetstormsecurity.org/1001-exploits/acidcatcms-disclose.txt
- http://www.exploit-db.com/exploits/10972
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55331



