CVE-2008-6770
YourPlace <= 1.0.2 - Unauthenticated Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6770. PoCs published by Osirys.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in YourPlace 0.5 (beta 1), including database disclosure, arbitrary data saving leading to RCE, arbitrary file upload, PHPInfo disclosure, and user account manipulation. The Perl script provided automates the RCE exploit by injecting malicious PHP code into a writable file.
Description
YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in YourPlace 0.5 (beta 1), including database disclosure, arbitrary data saving leading to RCE, arbitrary file upload, PHPInfo disclosure, and user account manipulation. The Perl script provided automates the RCE exploit by injecting malicious PHP code into a writable file.