CVE-2006-6890

Voodoo chat 1.0RC1b - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6890. PoCs published by bd0rk.

AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in Voodoo chat 1.0RC1b. The exploit involves accessing a specific file path to disclose user passwords stored in plaintext.

Description

Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.

Exploits (1)

exploitdb WRITEUP VERIFIED
by bd0rk · textwebappsphp
https://www.exploit-db.com/exploits/3044

This is a writeup describing an information disclosure vulnerability in Voodoo chat 1.0RC1b. The exploit involves accessing a specific file path to disclose user passwords stored in plaintext.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Voodoo chat 1.0RC1b
No auth needed
Prerequisites: Network access to the target server · Knowledge of the installation path of Voodoo chat
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/31221
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3044

Scores

EPSS 0.0209
EPSS Percentile 79.1%

Details

Status published
Products (1)
voc-project/voodoo_chat 1.0_rc1b
Published Dec 31, 2006
Tracked Since Feb 18, 2026