Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0249. PoCs published by Pouya_Server.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in RankEm software, including direct database download (info_leak), XSS, and cookie manipulation via crafted URLs. It provides functional PoC URLs for each vulnerability type.
Description
Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in RankEm software, including direct database download (info_leak), XSS, and cookie manipulation via crafted URLs. It provides functional PoC URLs for each vulnerability type.