Security Advisory
CVE-2012-5892
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.