CVE-2008-6382

Aspportal - Access Control

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6382. PoCs published by CWH Underground.

AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in ASPPortal Free Version, where the database file is accessible via a direct URL. No exploit code is provided, only the path to the vulnerable resource.

Description

ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb.

Exploits (1)

exploitdb WRITEUP VERIFIED
by CWH Underground · textwebappsasp
https://www.exploit-db.com/exploits/7316

This is a writeup describing an information disclosure vulnerability in ASPPortal Free Version, where the database file is accessible via a direct URL. No exploit code is provided, only the path to the vulnerable resource.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ASPPortal Free Version
No auth needed
Prerequisites: knowledge of the target path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32889
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/50372
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7316

Scores

EPSS 0.0251
EPSS Percentile 82.7%

Details

CWE
CWE-264
Status published
Products (1)
aspportal/aspportal 3.2.5
Published Mar 02, 2009
Tracked Since Feb 18, 2026