Release date:
Updated on:
Affected Systems:
Concrete5 Concrete5
Description:
--------------------------------------------------------------------------------
Concrete5 is a free open-source content management system.
The concrete5 member page has the user information leakage vulnerability. Remote attackers may exploit this vulnerability to list users in the system.
<* Source: Chris John Riley
Link: http://www.metasploit.com/modules/auxiliary/scanner/http/concrete5_member_list
Https://community.rapid7.com/community/metasploit/blog/2012/11/15/weekly-metasploit-update
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Concrete5
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.concrete5.org/