Exploitation Summary
EIP tracks 1 public exploit for CVE-2003-1213. PoCs published by JeiAr.
AI-analyzed exploit summary This is a vulnerability writeup describing multiple issues in MaxWebPortal, including XSS, insecure form fields, session cookie hijacking, database disclosure, and password reset vulnerabilities. No exploit code is provided, only descriptions and an example URL for database access.
Description
The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.
Exploits (1)
This is a vulnerability writeup describing multiple issues in MaxWebPortal, including XSS, insecure form fields, session cookie hijacking, database disclosure, and password reset vulnerabilities. No exploit code is provided, only descriptions and an example URL for database access.