CVE-2008-6355
ASPired2Protect - Unauthenticated Sensitive Information Exposure via Direct Database Download
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6355. PoCs published by AlpHaNiX.
AI-analyzed exploit summary This entry describes an information disclosure vulnerability in ASPired2Protect, where the database file is directly accessible via a URL. No exploit code is provided, only a reference to the vulnerable endpoint.
Description
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb.
Exploits (1)
This entry describes an information disclosure vulnerability in ASPired2Protect, where the database file is directly accessible via a URL. No exploit code is provided, only a reference to the vulnerable endpoint.