CVE-2008-2681
Realm CMS < 2.3 - Exposure of Sensitive Information via Direct Request to _db/compact.asp
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2681. PoCs published by BugReport.IR.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple vulnerabilities in Realm CMS 2.3 and prior, including broken authentication via cookie manipulation, SQL injection in the 'KeyWordsList' function, and XSS/DB path disclosure in '/cms/_db/compact.asp'. It provides specific exploit details and mitigation steps.
Description
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.
Exploits (1)
This is a detailed technical writeup describing multiple vulnerabilities in Realm CMS 2.3 and prior, including broken authentication via cookie manipulation, SQL injection in the 'KeyWordsList' function, and XSS/DB path disclosure in '/cms/_db/compact.asp'. It provides specific exploit details and mitigation steps.