CVE-2008-6940
TurnkeyForms Web Hosting Directory - Unauthenticated Sensitive Information Exposure via Direct Database Backup Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6940. PoCs published by G4N0K.
AI-analyzed exploit summary This is a technical writeup detailing multiple vulnerabilities in Turnkeyforms Web Hosting Directory, including insecure cookie handling, arbitrary database backup, and SQL injection authentication bypass. It provides code snippets and exploitation steps but does not include functional exploit code.
Description
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db.
Exploits (1)
This is a technical writeup detailing multiple vulnerabilities in Turnkeyforms Web Hosting Directory, including insecure cookie handling, arbitrary database backup, and SQL injection authentication bypass. It provides code snippets and exploitation steps but does not include functional exploit code.