Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5980. PoCs published by Pouya_Server.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Ocean12 Mailing List Manager Gold, including direct database download (info_leak), SQL injection, and XSS. The PoC provides specific URLs to trigger these vulnerabilities without requiring authentication.
Description
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Ocean12 Mailing List Manager Gold, including direct database download (info_leak), SQL injection, and XSS. The PoC provides specific URLs to trigger these vulnerabilities without requiring authentication.