CVE-2008-7069
All Club CMS <= 0.0.2 - Exposure of Sensitive Information via Direct Request to accms.dat
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7069. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit retrieves the database configuration file (`accms.dat`) from All Club CMS <= 0.0.2 by sending an HTTP GET request. It can either dump the entire file or parse specific database credentials (host, name, type, username, password).
Description
All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat.
Exploits (1)
This exploit retrieves the database configuration file (`accms.dat`) from All Club CMS <= 0.0.2 by sending an HTTP GET request. It can either dump the entire file or parse specific database credentials (host, name, type, username, password).