CVE-2008-5951

ASP Template Creature - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5951. PoCs published by ZoRLu.

AI-analyzed exploit summary This is a writeup detailing SQL injection and direct database download vulnerabilities in ASP Template Creature. It provides URLs for exploiting SQLi to dump admin credentials and a direct path to download the database file.

Description

ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ZoRLu · textwebappsphp
https://www.exploit-db.com/exploits/7339

This is a writeup detailing SQL injection and direct database download vulnerabilities in ASP Template Creature. It provides URLs for exploiting SQLi to dump admin credentials and a direct path to download the database file.

Classification
Writeup 90%
Attack Type
Sqli | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ASP Template Creature
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7339
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47085

Scores

EPSS 0.0223
EPSS Percentile 80.4%

Details

CWE
CWE-264
Status published
Products (1)
aspapps/template_creature _nil_
Published Jan 23, 2009
Tracked Since Feb 18, 2026