CVE-2009-0760
Team Board 1.x and 2.x - Unauthenticated Sensitive Information Exposure via Direct Database Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0760. PoCs published by Pouya_Server.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in Team Board software: an information disclosure (DD) allowing direct access to the database file and a reflected XSS via the 'lookname' parameter in online.asp. The PoC includes URLs to exploit both issues.
Description
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb.
Exploits (1)
The exploit demonstrates two vulnerabilities in Team Board software: an information disclosure (DD) allowing direct access to the database file and a reflected XSS via the 'lookname' parameter in online.asp. The PoC includes URLs to exploit both issues.