CVE-2008-6739
Todd Woolums ASP Download 1.03 - Unauthenticated Privilege Escalation via setupdownload.asp
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6739. PoCs published by Zigma.
AI-analyzed exploit summary This exploit describes an authentication bypass vulnerability in ASPDownload v1.03, allowing an attacker to reset admin credentials via the unprotected setupdownload.asp page. The attacker can then upload an ASP shell to achieve remote code execution.
Description
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
Exploits (1)
This exploit describes an authentication bypass vulnerability in ASPDownload v1.03, allowing an attacker to reset admin credentials via the unprotected setupdownload.asp page. The attacker can then upload an ASP shell to achieve remote code execution.