CVE-2008-6739

Todd Woolums ASP Download 1.03 - Unauthenticated Privilege Escalation via setupdownload.asp

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6739. PoCs published by Zigma.

AI-analyzed exploit summary This exploit describes an authentication bypass vulnerability in ASPDownload v1.03, allowing an attacker to reset admin credentials via the unprotected setupdownload.asp page. The attacker can then upload an ASP shell to achieve remote code execution.

Description

Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Zigma · textwebappsasp
https://www.exploit-db.com/exploits/5780

This exploit describes an authentication bypass vulnerability in ASPDownload v1.03, allowing an attacker to reset admin credentials via the unprotected setupdownload.asp page. The attacker can then upload an ASP shell to achieve remote code execution.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ASPDownload v1.03
No auth needed
Prerequisites: Access to the setupdownload.asp page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42983
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5780

Scores

EPSS 0.0225
EPSS Percentile 80.6%

Details

CWE
CWE-287
Status published
Products (1)
toddwoolums/asp_download 1.03
Published Apr 21, 2009
Tracked Since Feb 18, 2026