CVE-2009-0336
Katy Whitton BlogIt! - Unauthenticated Sensitive Information Exposure via Direct Database File Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0336. PoCs published by Pouya_Server.
AI-analyzed exploit summary The exploit demonstrates SQL injection, direct database download, and XSS vulnerabilities in BlogIt! by providing crafted URLs. It includes functional PoC URLs for each vulnerability type.
Description
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb. NOTE: some of these details are obtained from third party information.
Exploits (1)
The exploit demonstrates SQL injection, direct database download, and XSS vulnerabilities in BlogIt! by providing crafted URLs. It includes functional PoC URLs for each vulnerability type.