Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2753. PoCs published by kerem125.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in RunawaySoft Haber portal v1.0, allowing unauthorized access to the admin password via a crafted UNION SELECT query. The exploit also discloses the path to the database file.
Description
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in RunawaySoft Haber portal v1.0, allowing unauthorized access to the admin password via a crafted UNION SELECT query. The exploit also discloses the path to the database file.