Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6057. PoCs published by Cold Zero.
AI-analyzed exploit summary The exploit demonstrates SQL injection and database disclosure vulnerabilities in Liberum Help Desk. The SQL injection allows password resets via crafted input in the 'forgotpass.asp' page, while the database disclosure exposes the 'helpdesk2000.mdb' file directly.
Description
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
Exploits (1)
The exploit demonstrates SQL injection and database disclosure vulnerabilities in Liberum Help Desk. The SQL injection allows password resets via crafted input in the 'forgotpass.asp' page, while the database disclosure exposes the 'helpdesk2000.mdb' file directly.