CVE-2008-7063
Ocean12 FAQ Manager Pro - Unauthenticated Sensitive Data Exposure via Direct Database Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7063. PoCs published by Stack.
AI-analyzed exploit summary This exploit demonstrates a database disclosure vulnerability in Ocean12 FAQ Manager Pro by directly accessing the Microsoft Access database file (o12faq.mdb) via a predictable path. The vulnerability allows unauthorized access to sensitive data stored in the database.
Description
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for admin/o12faq.mdb.
Exploits (1)
This exploit demonstrates a database disclosure vulnerability in Ocean12 FAQ Manager Pro by directly accessing the Microsoft Access database file (o12faq.mdb) via a predictable path. The vulnerability allows unauthorized access to sensitive data stored in the database.