CVE-2008-6354
The Net Guys ASPired2poll - Unauthenticated Sensitive Information Exposure via Direct Database Download
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6354. PoCs published by AlpHaNiX.
AI-analyzed exploit summary This entry describes an information disclosure vulnerability in ASPired2poll, where the database file is directly accessible via a predictable URL. No exploit code is provided, only a reference to the exposed database path.
Description
The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb.
Exploits (1)
This entry describes an information disclosure vulnerability in ASPired2poll, where the database file is directly accessible via a predictable URL. No exploit code is provided, only a reference to the exposed database path.