Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5901. PoCs published by Ghost Hacker.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in iyzi Forum, where the database file (iyziforum.mdb) is accessible via a direct URL. No exploit code is provided, only a description and example URLs.
Description
iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in iyzi Forum, where the database file (iyziforum.mdb) is accessible via a direct URL. No exploit code is provided, only a description and example URLs.