CVE-2001-1170

AmTote International - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-1170. PoCs published by Gary O'Leary-Steele.

AI-analyzed exploit summary This exploit reads the world-readable homebet.log file from a default AmTote Homebet installation to extract account numbers and PINs. It demonstrates an information leakage vulnerability due to improper file permissions.

Description

AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gary O'Leary-Steele · perlremotemultiple
https://www.exploit-db.com/exploits/21115

This exploit reads the world-readable homebet.log file from a default AmTote Homebet installation to extract account numbers and PINs. It demonstrates an information leakage vulnerability due to improper file permissions.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: AmTote Homebet (version not specified)
No auth needed
Prerequisites: Access to the target system's file system · Default or misconfigured file permissions on homebet.log
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7186
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3370

Scores

EPSS 0.0757
EPSS Percentile 93.7%

Details

Status published
Products (1)
amtote_international/homebet
Published Sep 29, 2001
Tracked Since Feb 18, 2026