CVE-2008-5127
Ocean12 Contact Manager Pro 1.02 - Unprotected Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5127. PoCs published by Pouya_Server.
AI-analyzed exploit summary This exploit demonstrates SQL injection, database disclosure, and XSS vulnerabilities in Ocean12 Contact Manager Pro v1.02. It provides direct URLs to exploit these vulnerabilities without requiring authentication.
Description
Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.
Exploits (1)
This exploit demonstrates SQL injection, database disclosure, and XSS vulnerabilities in Ocean12 Contact Manager Pro v1.02. It provides direct URLs to exploit these vulnerabilities without requiring authentication.