CVE-2008-6321
CF Shopkart 5.2.2 - Unauthenticated Sensitive Information Exposure via Database File Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6321. PoCs published by AlpHaNiX.
AI-analyzed exploit summary The exploit demonstrates a blind SQL injection vulnerability in CF SHOPKART V5.2.2 via the 'Category' parameter and a database disclosure vulnerability by directly accessing the MDB file. The PoC provides specific URLs to exploit these vulnerabilities.
Description
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via a direct request.
Exploits (1)
The exploit demonstrates a blind SQL injection vulnerability in CF SHOPKART V5.2.2 via the 'Category' parameter and a database disclosure vulnerability by directly accessing the MDB file. The PoC provides specific URLs to exploit these vulnerabilities.