VYPR
Unrated severityNVD Advisory· Published Jan 6, 2009· Updated Apr 23, 2026

CVE-2008-5853

CVE-2008-5853

Description

Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain database credentials via a direct request for config.inc or (2) read database backups via a request for a backup/ URI.

Affected products

2
  • Chicomas/Chicomas2 versions
    cpe:2.3:a:chicomas:chicomas:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:chicomas:chicomas:*:*:*:*:*:*:*:*range: <=2.0.4
    • cpe:2.3:a:chicomas:chicomas:2.0.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.