CVE-2006-4897
CMtextS <= 1.0 - Unauthenticated Administrator Password Exposure via Insecure Web Root File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4897. PoCs published by Kacper.
AI-analyzed exploit summary This exploit reveals an information disclosure vulnerability in CMtextS <= 1.0, allowing unauthorized access to the admin password stored in a plaintext file. The PoC demonstrates how to retrieve the password and log in as an admin.
Description
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.
Exploits (1)
This exploit reveals an information disclosure vulnerability in CMtextS <= 1.0, allowing unauthorized access to the admin password stored in a plaintext file. The PoC demonstrates how to retrieve the password and log in as an admin.