CVE-2008-5932

CodeAvalanche FreeForum - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5932. PoCs published by Ghost Hacker.

AI-analyzed exploit summary This exploit discloses the path to a Microsoft Access database file (CAForum.mdb) in FreeForum, allowing unauthorized access to sensitive data. The vulnerability is due to improper access controls on the database file.

Description

CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ghost Hacker · textwebappsasp
https://www.exploit-db.com/exploits/7450

This exploit discloses the path to a Microsoft Access database file (CAForum.mdb) in FreeForum, allowing unauthorized access to sensitive data. The vulnerability is due to improper access controls on the database file.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FreeForum (version not specified)
No auth needed
Prerequisites: knowledge of the target path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33100
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7450
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4932

Scores

EPSS 0.0620
EPSS Percentile 92.6%

Details

CWE
CWE-264
Status published
Products (1)
codeavalanche/freeforum _nil_
Published Jan 21, 2009
Tracked Since Feb 18, 2026