CVE-2007-3061
Cactushop < 6 - Unauthenticated Sensitive Information Exposure via Direct Database Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3061. PoCs published by LionTurk.
AI-analyzed exploit summary This is a writeup describing a database disclosure vulnerability in CactuShop v6. The exploit details the path to the exposed database file (cactushop6.mdb) and provides a dork for finding vulnerable instances.
Description
Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb.
Exploits (1)
This is a writeup describing a database disclosure vulnerability in CactuShop v6. The exploit details the path to the exposed database file (cactushop6.mdb) and provides a dork for finding vulnerable instances.