CVE-2008-5773

Nukedit 4.9.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Cyber.Zer0 · textwebappsasp
https://www.exploit-db.com/exploits/7491

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7491
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4840
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33165

Scores

EPSS 0.0590
EPSS Percentile 90.7%

Details

CWE
CWE-264
Status published
Products (1)
nukedit/nukedit 4.9.8
Published Dec 30, 2008
Tracked Since Feb 18, 2026