CVE-2009-0498

Virtual GuestBook 2.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0498. PoCs published by Moudi.

AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in Virtual GuestBook v2.1, where the database file is accessible via a direct URL. No exploit code is provided, only the path to the exposed database.

Description

Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Moudi · textwebappsasp
https://www.exploit-db.com/exploits/7744

This is a writeup describing an information disclosure vulnerability in Virtual GuestBook v2.1, where the database file is accessible via a direct URL. No exploit code is provided, only the path to the exposed database.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Virtual GuestBook v2.1
No auth needed
Prerequisites: Knowledge of the target path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7744

Scores

EPSS 0.0227
EPSS Percentile 80.8%

Details

CWE
CWE-264
Status published
Products (1)
minitdesign/virtual_guestbook 2.1
Published Feb 10, 2009
Tracked Since Feb 18, 2026