CVE-2004-1786

PortalApp - Unauthenticated Sensitive Information Exposure via Direct Request to 8275.mdb

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1786. PoCs published by newbie6290.

AI-analyzed exploit summary This entry describes an information disclosure vulnerability in ASPapp PortalApp where user credentials are stored insecurely, allowing unauthorized access to sensitive data via direct URL access to the database file.

Description

PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.

Exploits (1)

exploitdb WRITEUP VERIFIED
by newbie6290 · textwebappsasp
https://www.exploit-db.com/exploits/23515

This entry describes an information disclosure vulnerability in ASPapp PortalApp where user credentials are stored insecurely, allowing unauthorized access to sensitive data via direct URL access to the database file.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ASPapp PortalApp
No auth needed
Prerequisites: Knowledge of the target URL structure
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1008627
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/14169
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9354

Scores

EPSS 0.0284
EPSS Percentile 85.1%

Details

Status published
Products (1)
iatek/portalapp
Published Jan 04, 2004
Tracked Since Feb 18, 2026