Cyber.Zer0

3 exploits Active since Dec 2008
CVE-2008-6147 EXPLOITDB text WRITEUP
Aspapp Forumapp - Access Control
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/8690.mdb or (2) data/8690BAK.mdb.
CVE-2008-5773 EXPLOITDB text WRITEUP
Nukedit 4.9.8 - Info Disclosure
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb.
CVE-2008-5852 EXPLOITDB text WORKING POC
Emefa Guestbook 3.0 - Info Disclosure
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.