CVE-2008-6199
2532gigs <= 1.2.2 - Unauthenticated Sensitive Information Exposure via Direct Backup Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6199. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This is a writeup describing an arbitrary remote database backup vulnerability in 2532|Gigs <= 1.2.2. The vulnerability allows unauthenticated users to trigger a database backup via a simple GET request to backup.php with the 'export=1' parameter.
Description
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control.
Exploits (1)
This is a writeup describing an arbitrary remote database backup vulnerability in 2532|Gigs <= 1.2.2. The vulnerability allows unauthenticated users to trigger a database backup via a simple GET request to backup.php with the 'export=1' parameter.